The company formally identifies and documents potential threats to applications before development begins
The threat-modeling policy facet requires threats to be documented before development starts on new applications and major changes, an early-lifecycle piece of A.8.25.
The threat-modeling policy facet requires threats to be documented for new applications before development starts, feeding directly into the requirements A.8.26 asks organizations to define.
The threat-modeling policy facet requires documented threats before development starts on new systems and major changes, an entry point into the secure engineering discipline A.8.27 asks for.