Added: Encryption of PII Data
Technically its HttpOnly, so i updated to reflect that.
Did not like that OWASP A7 only included 'use CSP, so updated that to reference more content from OWASP with some slight changes to reflect node, e.g use a template engine. Made some slight changes to the content for grammar improvements