A change management policy requires a 48-hour review window for all production changes. An SRE argues this policy creates more risk than it reduces. What is the BEST argument supporting the SRE's position?
-
A
Long review windows delay security patches and bug fixes, creating a larger window of vulnerability, and may incentivize engineers to batch changes in ways that increase blast radius
-
B
Engineers will simply bypass the review process if it is too slow, making it ineffective
-
C
48-hour reviews are only necessary for changes to customer-facing services, not internal infrastructure
-
D
Review processes should be automated and do not need human review windows