Require the developer of the system, system component, or system service to implement a plan for ongoing security control assessment.
No STIG checks reference this CCI.