A full-stack team is launching a feature that processes credit card data. Which risk treatment strategy is MOST appropriate for PCI DSS compliance gaps discovered during assessment?
-
A
Accept the risk and document it
-
B
Transfer the risk to a payment processor like Stripe
-
C
Avoid the risk by canceling the feature
-
D
Ignore the risk until after launch