Go to 7. Disconnected and Air-Gapped Operations
Crucible produces a Transfer Bundle containing the controlled content required for an authorized operation in a Disconnected Environment or Air-Gapped Environment.
The Transfer Bundle provides a defined unit for subsequent transfer across the applicable boundary. Producing the bundle does not authorize its export, physical movement, release, or import into another Security Domain.
Crucible selects the content required by the planned destination-environment activity.
The Transfer Bundle can contain:
The applicable lifecycle activity and requirements determine the content included in a particular Transfer Bundle.
Crucible does not include unrelated content merely because that content is available in the source environment.
Crucible assembles the selected content into an identifiable Transfer Bundle.
The assembly activity can include:
The Transfer Bundle can contain content originating from more than one authorized source. Inclusion in the same bundle does not merge the identity, revision, provenance, or governance of the individual items.
The Transfer Bundle contains the captured Dependencies required by the planned disconnected or air-gapped activity.
The included dependency information identifies, as applicable:
The bundle must contain the dependency content required by the destination activity rather than references that require unavailable connected access.
When an included artifact has associated Compliance Findings, Crucible includes the applicable findings in the Transfer Bundle.
The bundle preserves the relationship between each included Compliance Finding and the artifact or subject that the finding describes.
Including a Compliance Finding does not:
A change to the transferred artifact or its destination environment can require another assessment.
Crucible preserves the relationships needed to interpret the bundle after import.
These relationships can identify:
The destination environment must be able to distinguish the included content and reconstruct the relationships required by the subsequent lifecycle activity.
The produced Transfer Bundle has an identifiable representation.
The bundle-production result can identify:
The applicable transfer process can add separate export, custody, transport, inspection, release, or import records. Those records are not created merely by producing the Transfer Bundle.
Before transfer, the bundle can be reviewed to determine whether it contains the content selected for the planned destination activity.
The review can identify:
A complete bundle contains the selected content and relationships. Completeness does not independently authorize transfer across the boundary.
The Transfer-Bundle result identifies:
The produced Transfer Bundle becomes the controlled input to 7.3 Transfer Across the Boundary.
| Requirement | Statement |
|---|---|
| FR-DEPC-003 — Produce a Transfer Bundle |
Crucible SHALL produce a Transfer Bundle containing captured Build Dependencies. |
| FR-COMP-010a — Compliance Finding Transfer Bundle Inclusion |
Crucible SHALL include Compliance Findings in the Transfer Bundle containing the Artifacts to which the Compliance Findings apply. |
The linked leaf requirement pages remain the canonical sources.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.