In a heavily regulated industry, a new SDL policy requires every microservice to pass a security review before deployment. A team argues this slows releases unacceptably. The best governance response is to:
-
A
Define risk-tiered review tracks where lower-risk services use lighter-weight automated checks
-
B
Exempt microservices from the policy entirely
-
C
Increase the size of the security review team to match velocity
-
D
Replace security reviews with developer self-attestation only