Table of Contents

8.1 Select Compliance Criteria and Baselines

Go to 8. Compliance Operations

Before performing a Compliance Assessment, the applicable organization identifies the compliance criteria and Compliance Baseline against which Crucible evaluates the assessment subject.

Crucible supports defined Compliance Baselines, including:

The selection establishes the criteria for the assessment. It does not independently determine which legal, regulatory, contractual, security, or organizational obligations apply to the subject.

Identify the Assessment Subject

The compliance operation identifies the subject to which the selected criteria apply.

An assessment subject can include:

The subject remains identifiable by the information needed to distinguish it from another artifact, resource, environment, or revision.

Identify the Applicable Compliance Obligations

The responsible organization determines the compliance obligations applicable to the assessment subject.

Those obligations can derive from:

Crucible does not independently decide which obligation governs the subject.

Select a Compliance Baseline

The compliance operation selects a Compliance Baseline that represents the criteria applicable to the identified subject.

The selected Compliance Baseline identifies:

The assessment uses the identified Baseline revision rather than an unspecified or changing set of criteria.

DISA STIG Compliance Baselines

Crucible supports Compliance Baselines based on Defense Information Systems Agency Security Technical Implementation Guides.

A selected DISA STIG Compliance Baseline identifies the STIG content and revision applicable to the assessment subject.

Support for a DISA STIG Compliance Baseline does not establish that:

The applicable organization determines the selected STIG, tailoring, exceptions, and acceptance process.

FedRAMP Baseline Definitions

Crucible supports definitions representing applicable FedRAMP Baselines.

The selected definition identifies the FedRAMP Baseline and revision used to organize or relate the applicable compliance criteria.

Support for a FedRAMP Baseline Definition does not grant FedRAMP authorization or establish that the complete system satisfies FedRAMP requirements.

Custom Compliance Frameworks

Crucible supports organization-defined or otherwise approved custom compliance frameworks.

A custom compliance framework can represent criteria not completely addressed by a predefined Compliance Baseline.

The custom framework identifies:

A custom framework remains a controlled compliance definition rather than an undocumented collection of assessment checks.

Select the Applicable Criteria

The selected Compliance Baseline can contain more criteria than apply to a particular subject or assessment activity.

The responsible organization identifies the applicable criteria and any approved:

Crucible preserves the selected baseline and criteria as inputs to the subsequent Compliance Assessment.

An exclusion from the selected assessment does not by itself establish an approved compliance exception or risk acceptance.

Selection Result

The selection result identifies:

The selected criteria and Compliance Baseline become controlled inputs to 8.2 Perform Compliance Assessments.

Requirements Addressed

The linked leaf requirement pages remain the canonical sources.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.