====== 7.2 Produce the Transfer Bundle ====== [[dido:02-crusible:07-disconnected-and-air-gapped-operations:start|Go to 7. Disconnected and Air-Gapped Operations]] [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] produces a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] containing the controlled content required for an authorized operation in a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] or [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environment]]. The Transfer Bundle provides a defined unit for subsequent transfer across the applicable boundary. Producing the bundle does not authorize its export, physical movement, release, or import into another [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domain]]. ===== Select the Bundle Content ===== Crucible selects the content required by the planned destination-environment activity. The Transfer Bundle can contain: * Captured direct Dependencies * Captured transitive Dependencies * Dependency metadata * Dependency relationship information * Content required to populate Offline Repositories * Compliance Findings associated with included artifacts * Information needed to preserve the associations between Compliance Findings and the artifacts they describe The applicable lifecycle activity and requirements determine the content included in a particular Transfer Bundle. Crucible does not include unrelated content merely because that content is available in the source environment. ===== Assemble the Transfer Bundle ===== Crucible assembles the selected content into an identifiable Transfer Bundle. The assembly activity can include: - Select the captured dependency set - Select associated metadata - Select applicable Compliance Findings - Preserve required relationships among the included items - Create the bundle representation - Assign the Transfer Bundle identifier - Record the bundle-production result The Transfer Bundle can contain content originating from more than one authorized source. Inclusion in the same bundle does not merge the identity, revision, provenance, or governance of the individual items. ===== Include Captured Dependencies ===== The Transfer Bundle contains the captured Dependencies required by the planned disconnected or air-gapped activity. The included dependency information identifies, as applicable: * The Dependency * The selected version or revision * The Dependency type * The original source * Available integrity information * The relationship to the activity requiring the Dependency * Relationships among direct and transitive Dependencies The bundle must contain the dependency content required by the destination activity rather than references that require unavailable connected access. ===== Include Compliance Findings ===== When an included artifact has associated [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_finding|Compliance Findings]], Crucible includes the applicable findings in the Transfer Bundle. The bundle preserves the relationship between each included Compliance Finding and the artifact or subject that the finding describes. Including a Compliance Finding does not: * Change the recorded finding * Resolve the finding * Approve an exception * Establish risk acceptance * Grant operational authorization * Establish that the destination environment satisfies the same compliance criteria A change to the transferred artifact or its destination environment can require another assessment. ===== Preserve Bundle Relationships ===== Crucible preserves the relationships needed to interpret the bundle after import. These relationships can identify: * A Dependency and the activity requiring it * A direct Dependency and its transitive Dependencies * An artifact and its associated Compliance Findings * A finding and the subject assessed * An included item and its source * An included item and its selected revision * An included item and its integrity information The destination environment must be able to distinguish the included content and reconstruct the relationships required by the subsequent lifecycle activity. ===== Identify the Transfer Bundle ===== The produced Transfer Bundle has an identifiable representation. The bundle-production result can identify: * The Transfer Bundle identifier * The planned destination environment * The planned destination activity * The included Dependencies * The included Compliance Findings * The relationships among included items * The bundle format or representation * The bundle-production time * The bundle-production status * Any required content that was not included The applicable transfer process can add separate export, custody, transport, inspection, release, or import records. Those records are not created merely by producing the Transfer Bundle. ===== Review Bundle Completeness ===== Before transfer, the bundle can be reviewed to determine whether it contains the content selected for the planned destination activity. The review can identify: * Missing Dependencies * Missing transitive Dependencies * Missing Compliance Findings * Missing associations * Unresolved content * Content that is not authorized for inclusion * Content that cannot be represented in the bundle A complete bundle contains the selected content and relationships. Completeness does not independently authorize transfer across the boundary. ===== Transfer-Bundle Result ===== The Transfer-Bundle result identifies: * The produced Transfer Bundle * The selected bundle content * The captured Dependencies included * The Compliance Findings included * The preserved associations * The bundle-production status * Any missing or unresolved content The produced Transfer Bundle becomes the controlled input to [[dido:02-crusible:07-disconnected-and-air-gapped-operations:07-03-transfer-across-the-boundary|7.3 Transfer Across the Boundary]]. ===== Requirements Addressed ===== ^ Requirement ^ Statement ^ | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-10-dependency-capture-and-offline-transfer:fr-depc-003]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-10-dependency-capture-and-offline-transfer:fr-depc-003#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010a]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010a#Statement&noheader&nofooter&noeditbtn}} | The linked leaf requirement pages remain the canonical sources. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.