A change window disables a weak cipher on the city's API gateway and an old payment integration breaks. Leadership asks how to proceed securely. What is the best approach?
Select an answer to reveal the explanation.
Short Explanation
Hardening broke the old payment client—upgrade it if you can, or park a short, written risk exception while you finish the migration. Putting weak crypto back forever, or dropping TLS, is the wrong kind of fix.
Full Explanation
Cipher deprecation hardening can interrupt legacy integrations. Sound remediation prefers rolling forward to supported clients and protocols; when business continuity requires delay, a temporary exception with explicit risk acceptance and an expiration is preferable to permanently restoring weak ciphers or removing encryption. Ignoring the outage or forcing cleartext both fail security and operations goals.