Table of Contents

8.2 Perform Compliance Assessments

Go to 8. Compliance Operations

Crucible performs a Compliance Assessment by evaluating an identified subject against the compliance criteria selected in 8.1 Select Compliance Criteria and Baselines.

Crucible integrates with an applicable compliance-scanning tool through an operating-system-independent assessment abstraction. The abstraction separates the compliance operation from a particular scanning product or operating system.

Identify the Assessment Subject

Crucible identifies the subject to evaluate.

An assessment subject can include:

The subject remains identifiable throughout the assessment so the assessment result can be associated with the evaluated subject and revision.

Apply the Selected Criteria

The assessment uses the Compliance Baseline and criteria selected for the identified subject.

The assessment inputs identify:

Crucible does not independently determine which legal, regulatory, contractual, or organizational obligations apply to the subject.

Select the Assessment Provider

Crucible selects an applicable compliance-scanning or assessment tool through the supported provider interface.

The selected provider identifies:

Support for a compliance-scanning tool does not imply that the tool can evaluate every criterion in the selected Compliance Baseline.

Use the Compliance-Scanning Abstraction

The compliance-scanning abstraction defines a common means to invoke supported assessment providers.

The abstraction separates:

This separation allows Crucible to integrate with different compliance-scanning tools without defining the compliance workflow around one product-specific interface.

Support Multiple Operating Systems

Crucible supports compliance scanning for multiple operating systems through the compliance-scanning abstraction and applicable provider implementations.

An assessment provider can support:

Multiple-operating-system support does not require every provider to support every operating system.

The selected provider must support the operating system and subject type associated with the requested assessment.

Perform the Assessment

Crucible performs the assessment by:

  1. Identifying the assessment subject
  2. Applying the selected Compliance Baseline and criteria
  3. Selecting an applicable assessment provider
  4. Supplying the required provider-specific parameters
  5. Invoking the assessment provider
  6. Receiving the provider-native results
  7. Associating the results with the assessed subject and selected criteria
  8. Recording the assessment status

The provider performs the provider-specific scanning behavior. Crucible coordinates the assessment and maintains the relationship among the subject, criteria, provider, and returned results.

Handle Unsupported or Incomplete Assessments

Crucible records a condition that prevents the requested assessment from completing.

Such conditions can include:

Crucible does not treat an incomplete or unsupported assessment as a successful assessment.

Assessment Result

The assessment result identifies:

The assessment result provides the input used to produce the applicable Compliance Findings, reports, and Evidence under their respective requirements.

Requirements Addressed

Requirement Statement
FR-COMP-002 — Compliance Scanning Tool Integration

Crucible SHALL integrate with Compliance Scanning Tools.

FR-COMP-008a — Compliance Scanning Abstraction

Crucible SHALL provide a Compliance Scanning Abstraction.

FR-COMP-008b — Multiple Operating-System Support

Crucible SHALL evaluate two or more Operating Systems against defined compliance criteria.

The linked leaf requirement pages remain the canonical sources.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.