Table of Contents

3.3 Security Domains and Transfer Boundaries

Go to 3. Operational Environment

Crucible operates across environments governed by different security controls, access restrictions, information-handling rules, and transfer constraints.

A Security Domain establishes the security conditions under which information, software, infrastructure resources, and operational activities are controlled. Different Security Domains can apply different authorization, access, handling, auditing, retention, and transfer requirements.

A Transfer Boundary separates environments or Security Domains and governs the movement of permitted Artifacts, Dependencies, records, and supporting Evidence between them.

Security Domains

Crucible can perform applicable Operational Lifecycle activities within Classified Environments and Unclassified Environments.

The controls applicable to a Security Domain can affect:

Crucible applies the controls and restrictions established for the environment. Crucible does not establish the Security Classification, authorize access, or approve movement between Security Domains.

Transfer Boundaries

A Transfer Boundary governs movement between environments that do not share unrestricted access to the same resources.

A transfer can occur between:

The responsible organization determines whether a transfer is permitted and identifies the applicable Transfer Authorization, review process, handling controls, and transfer mechanism.

Crucible supports the controlled preparation and consumption of content associated with an authorized transfer. Crucible does not independently authorize the transfer.

Transfer Bundles

A Transfer Bundle provides a controlled package for moving identified Artifacts between environments.

The same Transfer Bundle retains its identity through:

  1. Creation in the source environment
  2. Review under the applicable Transfer Authorization
  3. Movement across the Transfer Boundary
  4. Receipt in the destination environment
  5. Import of identified Artifacts
  6. Recording of the resulting Provenance, Traceability, and Evidence

A Transfer Bundle can contain permitted content such as:

The content of a Transfer Bundle depends on the selected lifecycle activity and the applicable transfer controls.

Export and Import

In the source environment, Crucible creates a Transfer Bundle for identified Artifacts selected for transfer.

The export activity identifies:

In the destination environment, Crucible imports identified Artifacts from the Transfer Bundle.

The import activity identifies:

Import does not independently approve an Artifact for deployment, promotion, or operation. The applicable acceptance, security, compliance, and authorization processes determine whether the imported Artifact can be used.

Traceability Across Boundaries

Crucible preserves Traceability between the source and destination environments.

The traceability information can identify:

Preserving this information allows a reader or auditor to follow an Artifact from its source environment through transfer and import into the receiving environment.

Detailed transfer operations appear in Section 7: Disconnected and Air-Gapped Operations.

Requirements Addressed

Requirement Statement
OR-003a — Classified Environment Operations

Crucible SHALL execute each selected Operational Lifecycle activity within a Classified Environment.

OR-003b — Unclassified Environment Operations

Crucible SHALL execute each selected Operational Lifecycle activity within an Unclassified Environment.

OR-003c — Security Domain Resource Enforcement

Crucible SHALL prevent an operation from accessing a resource not authorized for the operation's governing Security Domain.

OR-003d — Security Domain Information Enforcement

Crucible SHALL prevent an operation from processing information not authorized within the operation's governing Security Domain.

OR-003e — Information Handling Rule Enforcement

Crucible SHALL prevent an operation from handling information in a manner prohibited by the Information Handling Rules governing that information.

OR-003f — Cross-Domain Transfer Control

Crucible SHALL transfer information between Security Domains only through an authorized Cross-Domain Transfer.

OR-003g — Security Domain Access Control

Crucible SHALL deny an access request that the governing Security Domain does not authorize for the requesting identity.

FR-AG-002 — Artifact Export Packages

Crucible SHALL create Transfer Bundles for export.

FR-AG-003 — Artifact Import Packages

Crucible SHALL import Transfer Bundles.

FR-AG-005 — Deployment Traceability Across Disconnected Environments

The linked leaf requirement pages remain the canonical sources.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.