====== FR-COMP-003 — Compliance Reporting ====== [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:start|Go to Crucible Compliance Management Requirements]] ===== Statement ===== [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL generate Compliance Reports. ===== Derived From ===== This requirement derives from: * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-COMP-003 The Original Requirement states: > //The system shall support compliance reporting.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] FR-COMP-003: * Replaces **The system** with the defined system name [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] * Changes **shall** to the established uppercase normative form **SHALL** * Replaces the weak phrase **support compliance reporting** with the observable behavior **generate Compliance Reports** No other substantive normalization is required. ===== Rationale ===== A Compliance Report communicates the results of compliance activities in a form that an actor or process can review, distribute, retain, or use as input to another activity. A Compliance Report can include: * The evaluated subject * The applicable [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_baseline|Compliance Baseline]] * The compliance criteria evaluated * Compliance Findings * Passed and failed evaluations * Severity classifications * Evaluation timestamps * Scanning-tool information * References to supporting [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] * Remediation information * Summary results This requirement establishes generation of Compliance Reports without prescribing: * A report format * A report schema * A presentation layout * A delivery mechanism * A report recipient * Report publication * Report retention * Report approval * Remediation behavior * Generation of separate Compliance Evidence Artifacts Separate requirements, architecture specifications, workflows, or reporting profiles define those subjects and behaviors. ===== Applies To ===== This requirement applies to: * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] * Compliance Reports * Compliance Findings * Compliance reporting operations ===== Verification ===== Verification confirms that: - Compliance results are selected for reporting - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] generates a Compliance Report from the selected compliance results - The generated Compliance Report identifies the evaluated subject - The generated Compliance Report communicates the selected compliance results - The resulting Compliance Report can be identified as the output of the tested reporting operation ===== Referenced By ===== The following pages reference this requirement: {{backlinks>.#dido:02-crusible}} ===== Implementation Status ===== Implemented and Verified ===== Requirement Status ===== Review and approve FR-COMP-003 as a leaf requirement. ---- ===== Issues ===== Determine whether Compliance Report requires a controlled definition in the shared Terms and Definitions corpus. Determine whether separate requirements define the minimum required contents of a Compliance Report. Determine whether separate requirements govern Compliance Report formats, retention, publication, and distribution. ---- ===== Notes for Editors ===== This requirement page retains the stable requirement identifier ''FR-COMP-003''. This page is a leaf requirement page and omits a trailing '':start'' from its namespace. The Statement preserves the approved source intent by requiring Crucible to generate Compliance Reports. Do not change **generate** to **display**, **publish**, **export**, **distribute**, or **retain** unless the controlling requirement identifies that behavior. Do not add a report format, schema, layout, recipient, delivery mechanism, retention period, approval process, or Evidence-generation obligation unless the controlling requirement changes through an approved requirements process. To reference this requirement Statement from another wiki page, insert: {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-003#Statement&noheader&nofooter&noeditbtn}} ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.