====== 8.2 Perform Compliance Assessments ====== [[dido:02-crusible:08-compliance-and-authorization-operations:start|Go to 8. Compliance Operations]] [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] performs a [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_assessment|Compliance Assessment]] by evaluating an identified subject against the compliance criteria selected in [[dido:02-crusible:08-compliance-and-authorization-operations:08-01-select-compliance-criteria-and-baselines|8.1 Select Compliance Criteria and Baselines]]. Crucible integrates with an applicable compliance-scanning tool through an operating-system-independent assessment abstraction. The abstraction separates the compliance operation from a particular scanning product or operating system. ===== Identify the Assessment Subject ===== Crucible identifies the subject to evaluate. An assessment subject can include: * A Machine Image * A Container Image * An Infrastructure Configuration * An Infrastructure Environment * A deployed resource * Another subject supported by the selected Compliance Baseline and assessment provider The subject remains identifiable throughout the assessment so the assessment result can be associated with the evaluated subject and revision. ===== Apply the Selected Criteria ===== The assessment uses the Compliance Baseline and criteria selected for the identified subject. The assessment inputs identify: * The assessment subject * The selected Compliance Baseline * The applicable criteria * The Baseline revision * Applicable parameters or tailoring information * The selected assessment provider Crucible does not independently determine which legal, regulatory, contractual, or organizational obligations apply to the subject. ===== Select the Assessment Provider ===== Crucible selects an applicable compliance-scanning or assessment tool through the supported provider interface. The selected provider identifies: * The scanning or assessment tool * The provider implementation * The provider revision * The supported subject type * The supported operating system * The provider-specific parameters * The criteria the provider can evaluate Support for a compliance-scanning tool does not imply that the tool can evaluate every criterion in the selected Compliance Baseline. ===== Use the Compliance-Scanning Abstraction ===== The compliance-scanning abstraction defines a common means to invoke supported assessment providers. The abstraction separates: * The identified assessment subject * The selected compliance criteria * The requested assessment operation * Provider-specific invocation details * Provider-native results This separation allows Crucible to integrate with different compliance-scanning tools without defining the compliance workflow around one product-specific interface. ===== Support Multiple Operating Systems ===== Crucible supports compliance scanning for multiple operating systems through the compliance-scanning abstraction and applicable provider implementations. An assessment provider can support: * One operating system * Multiple operating systems * Particular operating-system families * Particular versions or distributions * Particular subject types Multiple-operating-system support does not require every provider to support every operating system. The selected provider must support the operating system and subject type associated with the requested assessment. ===== Perform the Assessment ===== Crucible performs the assessment by: - Identifying the assessment subject - Applying the selected Compliance Baseline and criteria - Selecting an applicable assessment provider - Supplying the required provider-specific parameters - Invoking the assessment provider - Receiving the provider-native results - Associating the results with the assessed subject and selected criteria - Recording the assessment status The provider performs the provider-specific scanning behavior. Crucible coordinates the assessment and maintains the relationship among the subject, criteria, provider, and returned results. ===== Handle Unsupported or Incomplete Assessments ===== Crucible records a condition that prevents the requested assessment from completing. Such conditions can include: * No available provider supports the assessment subject * No available provider supports the subject operating system * The selected provider cannot evaluate one or more criteria * Required provider parameters are unavailable * The assessment subject is inaccessible * The provider returns an incomplete result * The assessment operation fails Crucible does not treat an incomplete or unsupported assessment as a successful assessment. ===== Assessment Result ===== The assessment result identifies: * The assessment subject * The subject revision * The selected Compliance Baseline * The applicable criteria * The assessment provider * The provider revision * The provider-specific parameters * The provider-native results * The assessment status * Any unsupported, incomplete, or failed evaluation The assessment result provides the input used to produce the applicable Compliance Findings, reports, and Evidence under their respective requirements. ===== Requirements Addressed ===== ^ Requirement ^ Statement ^ | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-002:start]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-002:start#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-008:fr-comp-008a]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-008:fr-comp-008a#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-008:fr-comp-008b]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-008:fr-comp-008b#Statement&noheader&nofooter&noeditbtn}} | The linked leaf requirement pages remain the canonical sources. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.