Exceptions and attribute configurations should be described by a policy file instead of hard-coded into the framework itself or into function calls.+Automatically sanitize any dynamic content before writing it into HTML, XML, or other documents that might be rendered by user agents that execute active content.