Go to 8. Compliance Operations
Before performing a Compliance Assessment, the applicable organization identifies the compliance criteria and Compliance Baseline against which Crucible evaluates the assessment subject.
Crucible supports defined Compliance Baselines, including:
The selection establishes the criteria for the assessment. It does not independently determine which legal, regulatory, contractual, security, or organizational obligations apply to the subject.
The compliance operation identifies the subject to which the selected criteria apply.
An assessment subject can include:
The subject remains identifiable by the information needed to distinguish it from another artifact, resource, environment, or revision.
The responsible organization determines the compliance obligations applicable to the assessment subject.
Those obligations can derive from:
Crucible does not independently decide which obligation governs the subject.
The compliance operation selects a Compliance Baseline that represents the criteria applicable to the identified subject.
The selected Compliance Baseline identifies:
The assessment uses the identified Baseline revision rather than an unspecified or changing set of criteria.
Crucible supports Compliance Baselines based on Defense Information Systems Agency Security Technical Implementation Guides.
A selected DISA STIG Compliance Baseline identifies the STIG content and revision applicable to the assessment subject.
Support for a DISA STIG Compliance Baseline does not establish that:
The applicable organization determines the selected STIG, tailoring, exceptions, and acceptance process.
Crucible supports definitions representing applicable FedRAMP Baselines.
The selected definition identifies the FedRAMP Baseline and revision used to organize or relate the applicable compliance criteria.
Support for a FedRAMP Baseline Definition does not grant FedRAMP authorization or establish that the complete system satisfies FedRAMP requirements.
Crucible supports organization-defined or otherwise approved custom compliance frameworks.
A custom compliance framework can represent criteria not completely addressed by a predefined Compliance Baseline.
The custom framework identifies:
A custom framework remains a controlled compliance definition rather than an undocumented collection of assessment checks.
The selected Compliance Baseline can contain more criteria than apply to a particular subject or assessment activity.
The responsible organization identifies the applicable criteria and any approved:
Crucible preserves the selected baseline and criteria as inputs to the subsequent Compliance Assessment.
An exclusion from the selected assessment does not by itself establish an approved compliance exception or risk acceptance.
The selection result identifies:
The selected criteria and Compliance Baseline become controlled inputs to 8.2 Perform Compliance Assessments.
| Requirement | Statement |
|---|---|
| FR-COMP-001 — Compliance Baseline Definitions |
Crucible SHALL define Compliance Baselines. |
| FR-COMP-005 — DISA STIG Compliance Baselines |
|
| FR-COMP-006 — FedRAMP Baseline Definitions |
|
| FR-COMP-007 — Custom Compliance Frameworks |
Crucible SHALL define user-defined Compliance Frameworks. |
The linked leaf requirement pages remain the canonical sources.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.