A development team adopts a widely used open source library that accelerates delivery of a revenue-critical release. The library has no active maintainer and no published vulnerability disclosure process. What should the security manager recommend FIRST?
A. Add the library to the software bill of materials for monitoring
B. Evaluate the component against secure acquisition and supply chain criteria
C. Fork the library so the organization controls future patching
D. Require compensating controls at the application perimeter
(Explain your answer for more points in the comments!)