The organization defines the set of users and resources over which the information system is to enforce nondiscretionary access control policies.
No STIG checks reference this CCI.