Crucible SHALL deny an access request that the governing Security Domain does not authorize for the requesting identity.
This requirement derives from:
The Original Requirement states:
The system SHALL support classified and unclassified deployment environments.[C1]
OR-003g isolates the obligation to deny access requests not authorized for the requesting identity within the governing Security Domain.
Operation within an authorized Classified Environment or Unclassified Environment does not authorize every identity to access every operation, resource, or information object within that environment.
A Security Domain establishes the authorization boundary governing identities and access requests within its scope.
OR-003g requires Crucible to deny an access request when the governing Security Domain does not authorize the requesting identity to perform the requested access.
This requirement applies to:
Verification confirms that:
The following pages reference this requirement:
Implemented and Verified.
Assess whether the current Crucible implementation denies access requests not authorized for the requesting identity within the governing Security Domain.
Review and approve OR-003g as a leaf requirement derived from OR-003.
Define how Crucible identifies and authenticates the identity making an access request.
Define how each access request identifies its governing Security Domain.
Define how the governing Security Domain represents authorization for an identity and requested access.
Define the access actions subject to authorization.
Define the behavior required when the requesting identity cannot be authenticated.
Define the behavior required when the governing Security Domain cannot be determined.
Define the behavior required when an authorization decision cannot be obtained.
Define the record required when Crucible denies an access request.
This requirement page should retain the stable requirement identifier OR-003g.
This page is a leaf requirement page and omits a trailing :start from its namespace.
OR-003g governs whether a requesting identity may perform requested access within a Security Domain.
The responsible authority establishes:
Changes to the Statement should preserve:
OR-003g differs from the other Security Domain requirements:
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003g#Statement&noheader&nofooter&noeditbtn}}
Do not rename this page after an external citation unless a redirect or move plan is in place.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.