The enforcement mechanism should deny all access by default, requiring explicit grants to specific users and roles for access to every page. This is done to prevent from :
Insufficient Transport Layer Protection
Unvalidated Redirects and Forwards
Failure to Restrict URL Access
Injection