A DevSecOps organization uses a 'policy as code' tool to enforce that no S3 buckets are publicly accessible. This practice best aligns with which compliance concept?
-
A
Reactive incident response
-
B
Shift-right security testing
-
C
Preventive guardrails enforced through automation
-
D
Manual change advisory board review