The organization defines the acceptance criteria that must be met when threat modeling of the information system is performed by the developer.
No STIG checks reference this CCI.