Mitigations should connect to specific threats

Every control should be traceable to something it is supposed to prevent.

Without that link, controls accumulate because they are good practice, and nobody can say what would break if one were removed. With it, you can answer the only questions that matter in a review: what does this stop, and what is still unaddressed.

More on Threat modelling