The organization requires information system developers to perform a vulnerability analysis to document risk mitigations.
No STIG checks reference this CCI.