A security team discovers that a vendor patch breaks a critical business application. What is the BEST immediate course of action?
-
A
Apply compensating controls and document a risk acceptance while working with the vendor on a fix
-
B
Roll back all patches immediately without documentation
-
C
Deploy the patch anyway and accept application downtime
-
D
Wait indefinitely until the vendor resolves the incompatibility