====== FR-COMP-010a — Compliance Finding Transfer Bundle Inclusion ====== [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:start|Go to FR-COMP-010 — Transferable Compliance Findings]] ===== Statement ===== [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL include Compliance Findings in the [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] containing the [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] to which the Compliance Findings apply. ===== Derived From ===== This requirement derives from: * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:start|FR-COMP-010 — Transferable Compliance Findings]] * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-COMP-010 The Original Requirement states: > //The system shall capture compliance findings into the transferable dependency/evidence bundle (see §4.10) so findings from connected build accompany artifacts into disconnected enclave.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] FR-COMP-010a: * Replaces **The system** with the defined system name [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] * Changes **shall** to the established uppercase normative form **SHALL** * Replaces **capture into** with the direct and observable behavior **include in** * Replaces **transferable dependency/evidence bundle** with the controlled term [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] * Extracts inclusion of Compliance Findings in a Transfer Bundle as an independently verifiable requirement * Assigns preservation of the relationship between Compliance Findings and Artifacts to FR-COMP-010b ===== Rationale ===== Compliance Findings describe compliance conditions associated with evaluated [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]]. Including the Compliance Findings in the same [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] as the affected Artifacts allows the findings to accompany those Artifacts during transfer. This requirement establishes Transfer Bundle inclusion without requiring Crucible to: * Generate the Compliance Findings * Validate the Compliance Findings * Resolve the Compliance Findings * Remediate the affected Artifacts * Reassess the affected Artifacts * Determine whether the affected Artifacts comply with a Compliance Baseline * Preserve the association between each Compliance Finding and its affected Artifact FR-COMP-010b governs preservation of the association between each Compliance Finding and the Artifact to which the finding applies. ===== Applies To ===== This requirement applies to: * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] * Compliance Findings * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundles]] * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] * Transfer Bundle creation operations ===== Verification ===== Verification confirms that: - One or more [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] with associated Compliance Findings are selected for testing - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] creates a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] containing the selected Artifacts - Crucible includes the associated Compliance Findings in the same Transfer Bundle - The Compliance Findings can be identified within the resulting Transfer Bundle - The selected Artifacts can be identified within the resulting Transfer Bundle ===== Referenced By ===== The following pages reference this requirement: {{backlinks>.#dido:02-crusible}} ===== Implementation Status ===== Implemented and Verified ===== Requirement Status ===== Review and approve FR-COMP-010a as a leaf requirement. ---- ===== Issues ===== Determine whether Compliance Finding requires a controlled definition in the shared Terms and Definitions corpus. Determine whether separate requirements define the representation of Compliance Findings within a Transfer Bundle. Determine whether separate requirements govern verification of Compliance Findings after Transfer Bundle import. ---- ===== Notes for Editors ===== This requirement page retains the derived requirement identifier ''FR-COMP-010a''. This page is a leaf requirement page and omits a trailing '':start'' from its namespace. The namespace for this requirement is: ''dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010a'' The Statement uses the controlling Transfer Bundle namespace: ''dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle'' The Statement addresses only inclusion of Compliance Findings and their affected Artifacts in the same Transfer Bundle. FR-COMP-010b governs preservation of the association between each Compliance Finding and the Artifact to which the Compliance Finding applies. Do not add finding generation, validation, resolution, remediation, reassessment, association-preservation, or compliance-decision obligations unless the controlling requirement changes through an approved requirements process. To reference this requirement Statement from another wiki page, insert: {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010a#Statement&noheader&nofooter&noeditbtn}} ---- © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.