The organization requires that developers perform a vulnerability analysis for the information system at an organization-defined breadth/depth.
No STIG checks reference this CCI.