Once you have modelled your threats, it's time to turn that information into security requirements.
A prerequisite for meeting such requirements is implementing a disciplined Software Development
Life-Cycle (SDLC), so you can verify the code you write is actually solving the correct problems.