The organization requires the threat modeling performed by the developers employ organization-defined tools and methods.
No STIG checks reference this CCI.