An SC-100 architect is evaluating an organization's security posture using the MITRE ATT&CK framework. What is the PRIMARY purpose of mapping security controls to ATT&CK techniques?
-
A
To satisfy regulatory audit requirements by demonstrating control coverage documentation
-
B
To identify gaps where adversary techniques are not covered by existing defenses and prioritize control improvements
-
C
To generate automated threat intelligence reports for executive dashboards
-
D
To classify all security incidents by technique ID for SIEM correlation rules