A development team discovers a critical security vulnerability in a third-party library used in production. Which risk response strategy is MOST appropriate?
-
A
Accept the risk and document it
-
B
Transfer the risk to the vendor
-
C
Mitigate by patching or replacing the library immediately
-
D
Avoid by shutting down the application