Table of Contents

5.7 Preserve Evidence and Lifecycle Records

Go to 5. Operational Concept

Crucible preserves Evidence and lifecycle records produced during baseline composition, image construction, dependency capture, compliance assessment, deployment, and validation.

Preservation maintains the relationship among:

A preserved record documents what occurred during a Crucible lifecycle activity. The record does not independently establish approval, authorization, certification, risk acceptance, or operational suitability.

Evidence Generation

Crucible generates Evidence when an applicable lifecycle activity produces information needed to support evaluation, review, reproduction, audit, or authorization-related processes.

Evidence can include:

The applicable requirement determines which Evidence Crucible produces for a particular activity.

Evidence Identification

Each Evidence artifact remains identifiable and associated with the lifecycle activity that produced it.

An Evidence record can identify:

An Evidence artifact does not become authoritative merely because Crucible preserves it. The applicable governance process determines how an organization evaluates and uses the Evidence.

Lifecycle Records

A lifecycle record documents an identified Crucible activity and its result.

Lifecycle records can describe:

Crucible preserves sufficient information to relate a lifecycle record to the subject, inputs, operation, result, and supporting Evidence.

Provenance

Provenance identifies the origin and history of an artifact, record, or lifecycle result.

Crucible preserves Provenance information needed to determine:

Provenance enables a reviewer to follow the history of a lifecycle result without treating undocumented assumptions as part of the record.

Traceability

Traceability preserves navigable relationships among lifecycle inputs, activities, outputs, requirements, findings, and Evidence.

Traceability can relate:

Traceability does not require all lifecycle information to reside in one physical repository. The preserved relationships must allow the associated records to remain identifiable and retrievable.

Integrity Protection

Crucible preserves integrity information for Evidence and lifecycle records when the applicable requirement requires integrity verification.

Integrity protection can include:

An integrity result determines whether the evaluated content corresponds to its recorded integrity value. It does not independently establish the correctness or sufficiency of the content.

Preservation and Retrieval

Crucible preserves Evidence and lifecycle records in an authorized repository or record store.

Preservation maintains:

Authorized actors and systems can retrieve preserved Evidence and lifecycle records through the applicable Crucible interface and access controls.

The governing organization defines retention periods, legal holds, disposal rules, classification restrictions, and other records-management obligations.

Transfer Between Environments

Evidence and lifecycle records can accompany an artifact or operational result when Crucible transfers the subject between environments.

The applicable Transfer Bundle can include:

Crucible preserves the association between a transferred subject and its related Compliance Findings and Evidence.

Transfer does not change the recorded meaning, result, or status of the Evidence. A change to the transferred subject or destination environment can require additional assessment or validation.

Authorization-Supporting Evidence

Crucible can preserve Evidence used to support:

Crucible provides and preserves the supporting Evidence. Crucible does not grant Accreditation, Operational Approval, risk acceptance, or an Authority to Operate.

Preservation Result

The preservation result records:

The preserved Evidence and lifecycle records remain available for subsequent review, assessment, validation, transfer, reproduction, audit, governance, or authorization-supporting activities.

Requirements Addressed

Requirement Statement
FR-COMP-009a — Security Control Traceability Matrix Evidence

Crucible SHALL generate Security-Control Implementation Evidence for inclusion in a Security Control Traceability Matrix (SCTM).

FR-COMP-009b — Risk Management Framework Evidence

Crucible SHALL generate Security-Control Implementation Evidence for use in Risk Management Framework (RMF) activities.

FR-COMP-009c — Authorization to Operate Evidence

Crucible SHALL generate Security-Control Implementation Evidence for use in Authorization to Operate (ATO) activities.

FR-COMP-010a — Compliance Finding Transfer Bundle Inclusion

Crucible SHALL include Compliance Findings in the Transfer Bundle containing the Artifacts to which the Compliance Findings apply.

FR-COMP-010b — Compliance Finding Association Preservation

Crucible SHALL preserve the association between each Compliance Finding and the Artifact to which the Compliance Finding applies when transferring them in a Transfer Bundle from a Connected Environment to a Disconnected Environment.

The linked leaf requirement pages remain the canonical sources.

The confirmed requirements above directly support Compliance Evidence and preservation of transferred Compliance Finding associations. Any separate Evidence Management, provenance, traceability, audit-record, or lifecycle-record leaf requirements should also be added when their exact identifiers and namespaces are confirmed.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.