An organization integrates automated security testing into its CI/CD pipeline. Shortly after deployment, build times increase significantly, and developers begin bypassing security checks to meet release deadlines.
Senior management is concerned about both security and delivery velocity.
What should the security lead do FIRST?
A. Disable automated security testing to restore build speed
B. Tune and prioritize security tests based on risk and criticality
C. Enforce strict policy violations and discipline developers
D. Move security testing entirely to post-deployment monitoring