Defines the thresholds to which the developer of the system, system component, or system service is required to reduce attack surfaces.
No STIG checks reference this CCI.