On our own site we only have Content Security Policy, XSS-Protection and Referrer Policy = Same Origin enabled.
I really cannot recommend any standard setting as this is not ZP specific and depends. As you noticed there are docs linked for more info.