====== 4.3 External Systems ====== [[dido:02-crusible:04-actors-and-responsibilities:start|Go to 4. Actors and Responsibilities]] External Systems are systems outside the [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] boundary that provide inputs, receive outputs, perform provider-specific operations, or support an authorized Crucible lifecycle activity. An External System does not become part of Crucible merely because Crucible exchanges information with it or invokes one of its interfaces. Crucible controls the interaction through defined interfaces, Provider Implementations, authorization rules, and lifecycle records. ===== Deployment Platforms and Providers ===== Deployment Platforms and provider systems supply the infrastructure services used to realize an [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environment]]. Depending on the supported [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_target|Deployment Target]], these systems can include: * Commercial cloud platforms * Private cloud platforms * On-premises infrastructure platforms * Virtualization platforms * Container-orchestration platforms * Bare-metal provisioning systems Crucible separates provider-independent intent from provider-specific interfaces and behavior. Provider-specific dependencies remain confined to the applicable Provider Implementation. ===== Source and Artifact Repositories ===== Repositories provide or receive controlled lifecycle inputs and outputs. These systems can include: * Source repositories * [[dido:99_annexes:annex-b-terms-and-definitions:b:baseline|Baseline]] repositories * Software package repositories * Container registries * Machine-image repositories * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency_store|Dependency Stores]] * [[dido:99_annexes:annex-b-terms-and-definitions:o:offline_repository|Offline Repositories]] Crucible identifies the repository, resource, version, and integrity information associated with an input or output when the applicable requirement requires that information. A repository available in a [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environment]] might not be available in a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] or [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environment]]. Required content must therefore be captured, preserved, transferred, and made available through authorized local systems before disconnected execution. ===== Identity and Access Systems ===== Identity and access systems authenticate actors and provide information used to enforce access restrictions. Crucible relies on the applicable environment and Security Domain to establish: * Actor identity * Assigned roles or permissions * Permitted resources * Permitted operations * Applicable access restrictions Crucible applies the authorization information presented through approved integrations. Crucible does not independently grant organizational access rights or redefine the access policy of an external identity system. ===== Security and Assessment Systems ===== External security and assessment systems can provide criteria, assessment functions, or results used during Crucible lifecycle activities. These systems can include: * Security-content repositories * Configuration-assessment tools * Vulnerability-assessment tools * Compliance-assessment tools * Malware-analysis tools * Digital-signature and integrity-verification services Crucible records the relationship between an assessment activity, the assessed subject, the applicable criteria, the tool or service used, and the resulting findings or [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] when required. An external assessment result does not independently grant approval, authorization, or risk acceptance. ===== Logging and Audit Systems ===== External logging and audit systems can receive lifecycle events, operation results, access events, assessment results, and other records produced through Crucible. These interactions support: * Operational monitoring * Security monitoring * Incident review * [[dido:99_annexes:annex-b-terms-and-definitions:a:auditability|Auditability]] * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] * Preservation of lifecycle records The applicable Security Domain determines which information can be transmitted to an external logging or audit system. ===== Transfer Systems ===== Transfer systems support authorized movement across a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundary]]. These systems can include approved removable media, controlled transfer services, cross-domain mechanisms, receiving repositories, or other organization-approved transfer facilities. Crucible prepares or consumes the applicable [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] and records the associated lifecycle information. The external transfer system and responsible personnel perform the transfer according to the governing authorization and handling procedures. ===== Interaction Boundaries ===== Crucible interactions with External Systems must preserve the controls applicable to the operation and environment. External Systems do not independently: * Override Crucible authorization controls * Introduce unauthorized resources into an operation * bypass Security Domain restrictions * Change the approved content of a Transfer Bundle * Grant Accreditation, Operational Approval, or an Authority to Operate * Replace the canonical Crucible lifecycle and traceability records Crucible records sufficient information to identify the External System and its role in an operation when the applicable requirement requires that identification. ===== Requirements Addressed ===== ^ Requirement ^ Statement ^ | [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-003:mo-003d]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-003:mo-003d#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004c]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004c#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004d]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004d#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003c]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003c#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003d]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003d#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003g]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003g#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003#Statement&noheader&nofooter&noeditbtn}} | The linked leaf requirement pages remain the canonical sources. This page describes External Systems only to the extent supported by the applicable requirements and does not establish additional integrations or external-system capabilities. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.