====== 8.5 Transfer Compliance Findings ====== [[dido:02-crusible:08-compliance-and-authorization-operations:start|Go to 8. Compliance Operations]] [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] includes applicable [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_finding|Compliance Findings]] in a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] and preserves the association between each transferred finding and the artifact or subject that the finding describes. Transferring a Compliance Finding makes the recorded result available in the destination environment. Transfer does not change the meaning, status, or applicability of the finding. ===== Identify the Transferred Subject ===== Crucible identifies the artifact or subject associated with the Compliance Findings selected for transfer. The subject remains distinguishable from: * Other artifacts in the Transfer Bundle * Other revisions of the same artifact * Artifacts already present in the destination environment * Artifacts transferred through another Transfer Bundle * Artifacts subsequently rebuilt in the destination environment The identifying information supports preservation of the association between the transferred subject and its Compliance Findings. ===== Select the Applicable Compliance Findings ===== Crucible selects the Compliance Findings associated with the subject included in the Transfer Bundle. Each selected finding remains associated with: * The assessed subject * The subject revision, when applicable * The compliance criterion evaluated * The recorded assessment result * The assessment that produced the finding Crucible does not associate a finding with another subject merely because both subjects appear in the same Transfer Bundle. ===== Include Compliance Findings in the Transfer Bundle ===== Crucible includes the selected Compliance Findings in the Transfer Bundle carrying the associated subject. The bundle representation identifies: * The transferred subject * The applicable Compliance Findings * The relationship between each finding and the subject * The Transfer Bundle carrying the subject and findings The Transfer Bundle can contain findings associated with more than one subject. Crucible preserves each subject-to-finding association independently. ===== Preserve Finding Associations ===== Crucible preserves the association between each Compliance Finding and the subject that the finding describes. The preserved association allows the destination environment to determine: * Which subject the finding applies to * Which revision was assessed, when applicable * Which findings apply to another subject * Whether the subject and finding arrived through the same Transfer Bundle The transfer process does not convert the findings into an unidentified or unassociated collection of assessment results. ===== Maintain the Recorded Meaning ===== Transfer does not: * Change the result recorded by a Compliance Finding * Resolve or remediate a finding * Approve an exception or deviation * Establish risk acceptance * Grant Operational Approval * Grant an Authority to Operate * Establish that the destination environment satisfies the assessed criterion The responsible organization determines how transferred Compliance Findings contribute to review, remediation, governance, or authorization activities. ===== Relationship to Imported and Rebuilt Artifacts ===== A transferred Compliance Finding remains associated with the subject that was assessed. If Crucible rebuilds an artifact in the destination environment, the rebuilt artifact constitutes a separate lifecycle result. Compliance Findings associated with the transferred source artifact do not automatically apply to: * The rebuilt artifact * A later artifact revision * The deployed environment * Other destination resources * The complete operational system The applicable compliance requirements determine whether the rebuilt or deployed subject requires another assessment. ===== Transfer Result ===== The transfer result identifies: * The transferred subject * The subject identifier or revision * The Compliance Findings included * The Transfer Bundle carrying the subject and findings * The preserved subject-to-finding associations * Any missing or unresolved association * The transfer-inclusion status The transferred Compliance Findings become available for destination-side review without changing their recorded meaning or applying them to a different subject. ===== Requirements Addressed ===== ^ Requirement ^ Statement ^ | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010a]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010a#Statement&noheader&nofooter&noeditbtn}} | | [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010b]] | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010b#Statement&noheader&nofooter&noeditbtn}} | The linked leaf requirement pages remain the canonical sources. ===== Notes for Editors ===== The approved requirements establish inclusion of Compliance Findings in a Transfer Bundle and preservation of their association with the subjects they describe. They do not explicitly establish transfer of Compliance Evidence Artifacts. Evidence should be added to the title and content only when an approved leaf requirement requires its inclusion or transfer. ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.