A client insists on using a module with a full security advisory and no available patch. What should a professional Drupal developer do?
-
A
Install it anyway since the client accepts the risk verbally
-
B
Refuse all work on the project
-
C
Document the risk formally, obtain written client approval, and implement a compensating control
-
D
Remove the functionality entirely without consulting the client