Require the developer of the system, system component, or system service to perform threat modeling and vulnerability analyses during development.
No STIG checks reference this CCI.