The organization defines the breadth/depth at which threat modeling for the information system must be performed by developers.
No STIG checks reference this CCI.