Go to 8. Compliance Operations
Crucible generates Compliance Evidence Artifacts from the applicable compliance activities and results.
The generated Evidence supports review of the assessed subject, the selected compliance criteria, and the results produced by the Compliance Assessment.
Evidence generation does not independently establish compliance, approve an exception, accept risk, grant Operational Approval, or issue an Authority to Operate.
Crucible associates each generated Evidence Artifact with the subject to which the Evidence applies.
The Evidence subject can include:
The subject remains identifiable so an authorized reviewer can determine which artifact, resource, environment, or revision the Evidence describes.
The generated Evidence remains associated with the compliance activity that produced it.
The association can identify:
The Evidence does not apply automatically to another subject or revision.
Crucible generates Compliance Evidence Artifacts from the applicable assessment inputs and results.
A Compliance Evidence Artifact can contain or reference:
The applicable requirement does not prescribe one Evidence format, schema, repository, or presentation technology.
Crucible generates Evidence supporting Security Control Traceability Matrix activities.
The Evidence can relate:
The responsible organization determines how the Evidence contributes to its Security Control Traceability Matrix.
Crucible does not independently determine that a security control is fully implemented, inherited, accepted, or approved.
Crucible generates Evidence supporting Risk Management Framework activities.
The Evidence can support review of:
The responsible organization determines how the Evidence applies within its Risk Management Framework process.
Crucible does not select the organization’s risk response, approve a remediation plan, or accept residual risk.
Crucible generates Evidence supporting Authority to Operate activities.
The Evidence can provide information used by authorized personnel to evaluate:
Crucible supports the authorization process by generating Evidence. Crucible does not grant, deny, renew, suspend, or revoke an Authority to Operate.
During generation, Crucible maintains the relationship among:
These associations allow an authorized reviewer to determine what the Evidence describes and why Crucible generated it.
This capability does not establish a general requirement to preserve, retain, archive, or retrieve the generated Evidence after its production.
The Evidence-generation result identifies:
The generated Evidence becomes available to the applicable review, Security Control Traceability Matrix, Risk Management Framework, or Authority to Operate activity.
| Requirement | Statement |
|---|---|
| FR-COMP-004 — Compliance Evidence Artifacts |
|
| FR-COMP-009a — Security Control Traceability Matrix Evidence |
Crucible SHALL generate Security-Control Implementation Evidence for inclusion in a Security Control Traceability Matrix (SCTM). |
| FR-COMP-009b — Risk Management Framework Evidence |
Crucible SHALL generate Security-Control Implementation Evidence for use in Risk Management Framework (RMF) activities. |
| FR-COMP-009c — Authorization to Operate Evidence |
Crucible SHALL generate Security-Control Implementation Evidence for use in Authorization to Operate (ATO) activities. |
The linked leaf requirement pages remain the canonical sources.
The approved requirements establish Evidence generation and authorization-supporting Evidence. They do not establish Evidence preservation, retention, archival storage, or retrieval.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.