Go to 8. Compliance Operations
Crucible performs a Compliance Assessment by evaluating an identified subject against the compliance criteria selected in 8.1 Select Compliance Criteria and Baselines.
Crucible integrates with an applicable compliance-scanning tool through an operating-system-independent assessment abstraction. The abstraction separates the compliance operation from a particular scanning product or operating system.
Crucible identifies the subject to evaluate.
An assessment subject can include:
The subject remains identifiable throughout the assessment so the assessment result can be associated with the evaluated subject and revision.
The assessment uses the Compliance Baseline and criteria selected for the identified subject.
The assessment inputs identify:
Crucible does not independently determine which legal, regulatory, contractual, or organizational obligations apply to the subject.
Crucible selects an applicable compliance-scanning or assessment tool through the supported provider interface.
The selected provider identifies:
Support for a compliance-scanning tool does not imply that the tool can evaluate every criterion in the selected Compliance Baseline.
The compliance-scanning abstraction defines a common means to invoke supported assessment providers.
The abstraction separates:
This separation allows Crucible to integrate with different compliance-scanning tools without defining the compliance workflow around one product-specific interface.
Crucible supports compliance scanning for multiple operating systems through the compliance-scanning abstraction and applicable provider implementations.
An assessment provider can support:
Multiple-operating-system support does not require every provider to support every operating system.
The selected provider must support the operating system and subject type associated with the requested assessment.
Crucible performs the assessment by:
The provider performs the provider-specific scanning behavior. Crucible coordinates the assessment and maintains the relationship among the subject, criteria, provider, and returned results.
Crucible records a condition that prevents the requested assessment from completing.
Such conditions can include:
Crucible does not treat an incomplete or unsupported assessment as a successful assessment.
The assessment result identifies:
The assessment result provides the input used to produce the applicable Compliance Findings, reports, and Evidence under their respective requirements.
| Requirement | Statement |
|---|---|
| FR-COMP-002 — Compliance Scanning Tool Integration |
Crucible SHALL integrate with Compliance Scanning Tools. |
| FR-COMP-008a — Compliance Scanning Abstraction |
Crucible SHALL provide a Compliance Scanning Abstraction. |
| FR-COMP-008b — Multiple Operating-System Support |
Crucible SHALL evaluate two or more Operating Systems against defined compliance criteria. |
The linked leaf requirement pages remain the canonical sources.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.