====== OR-003g — Security Domain Access Control ======
[[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:start|Go to OR-003 — Classified and Unclassified Environments]]
===== Statement =====
[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL deny an access request that the governing [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domain]] does not authorize for the requesting identity.
===== Derived From =====
This requirement derives from:
* [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:start|OR-003 — Classified and Unclassified Environments]]
* Crucible System Requirements Specification, Version 1.1 Draft, Operational Requirements, OR-003
The Original Requirement states:
> //The system SHALL support classified and unclassified deployment environments.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
OR-003g isolates the obligation to deny access requests not authorized for the requesting identity within the governing Security Domain.
===== Rationale =====
Operation within an authorized [[dido:99_annexes:annex-b-terms-and-definitions:c:classified_environment|Classified Environment]] or [[dido:99_annexes:annex-b-terms-and-definitions:u:unclassified_environment|Unclassified Environment]] does not authorize every identity to access every operation, resource, or information object within that environment.
A [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domain]] establishes the authorization boundary governing identities and access requests within its scope.
OR-003g requires [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] to deny an access request when the governing Security Domain does not authorize the requesting identity to perform the requested access.
===== Applies To =====
This requirement applies to:
* [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]
* [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domains]]
* Requesting identities
* Access requests
* Crucible operations
* Resources accessed through Crucible
* Information accessed through Crucible
* [[dido:99_annexes:annex-b-terms-and-definitions:c:classified_environment|Classified Environments]]
* [[dido:99_annexes:annex-b-terms-and-definitions:u:unclassified_environment|Unclassified Environments]]
===== Verification =====
Verification confirms that:
- Each tested access request identifies the requesting identity
- Each tested access request identifies its governing [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domain]]
- Each tested access request identifies the requested access
- The governing Security Domain provides an authorization decision for the requesting identity and requested access
- [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] permits an access request authorized for the requesting identity
- Crucible denies an access request not authorized for the requesting identity
- Crucible denies an access request when the requesting identity cannot be determined
- Crucible denies an access request when the governing Security Domain cannot be determined
- Crucible records each access denial
- Each denial record identifies the requesting identity, governing Security Domain, requested access, and denial result
===== Referenced By =====
The following pages reference this requirement:
{{backlinks>.#dido:02-crusible}}
===== Delivery Phase =====
Implemented and Verified.
===== Implementation Status =====
Assess whether the current Crucible implementation denies access requests not authorized for the requesting identity within the governing Security Domain.
===== Requirement Status =====
Review and approve OR-003g as a leaf requirement derived from OR-003.
----
===== Issues =====
Define how Crucible identifies and authenticates the identity making an access request.
Define how each access request identifies its governing Security Domain.
Define how the governing Security Domain represents authorization for an identity and requested access.
Define the access actions subject to authorization.
Define the behavior required when the requesting identity cannot be authenticated.
Define the behavior required when the governing Security Domain cannot be determined.
Define the behavior required when an authorization decision cannot be obtained.
Define the record required when Crucible denies an access request.
----
===== Notes for Editors =====
This requirement page should retain the stable requirement identifier ''OR-003g''.
This page is a leaf requirement page and omits a trailing '':start'' from its namespace.
OR-003g governs whether a requesting identity may perform requested access within a Security Domain.
The responsible authority establishes:
* The recognized identity types
* The authentication requirements
* The roles or attributes associated with an identity
* The access actions subject to authorization
* The authorization policy
* The conditions under which access is permitted or denied
Changes to the Statement should preserve:
* [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor
* Denial as the required behavior
* An access request as the evaluated subject
* The requesting identity as the entity seeking access
* The governing [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domain]] as the source of authorization
OR-003g differs from the other Security Domain requirements:
* OR-003c prevents an operation from accessing an unauthorized resource
* OR-003d prevents an operation from processing unauthorized information
* OR-003e enforces the Information Handling Rules governing authorized information
* OR-003f controls information transfer between Security Domains
* OR-003g determines whether the requesting identity is authorized to perform the requested access
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003g#Statement&noheader&nofooter&noeditbtn}}
Do not rename this page after an external citation unless a redirect or move plan is in place.
----
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.