Table of Contents

FR-COMP-002 — Compliance Scanning Tool Integration

Go to Crucible Compliance Management Requirements

Statement

Crucible SHALL integrate with Compliance Scanning Tools.

Derived From

This requirement derives from:

The Original Requirement states:

The system shall integrate with compliance scanning tools.[C1]

FR-COMP-002:

No other substantive normalization is required.

Rationale

Compliance Scanning Tools evaluate systems, configurations, images, workloads, or other subjects against defined compliance criteria.

Integration allows Crucible to use externally implemented scanning capabilities without incorporating each scanning engine directly into the core Crucible implementation.

An integration can involve:

This requirement establishes integration with Compliance Scanning Tools without prescribing:

Separate requirements, architecture specifications, workflows, or interface definitions govern those subjects and behaviors.

Applies To

This requirement applies to:

Verification

Verification confirms that:

  1. A Compliance Scanning Tool is selected for testing
  2. Crucible exchanges the information required to use the selected Compliance Scanning Tool
  3. Crucible initiates or otherwise causes the selected Compliance Scanning Tool to perform a compliance scan
  4. Crucible receives an observable result from the selected Compliance Scanning Tool
  5. The observed interaction demonstrates integration with the selected Compliance Scanning Tool

Referenced By

The following pages reference this requirement:

Implementation Status

Implemented and Verified

Requirement Status

Review and approve FR-COMP-002 as a leaf requirement.


Issues

Determine whether Compliance Scanning Tool requires a controlled definition in the shared Terms and Definitions corpus.

Determine whether separate requirements define the information exchanged with a Compliance Scanning Tool.

Determine whether separate requirements govern preservation and processing of Compliance Findings returned by a Compliance Scanning Tool.


Notes for Editors

This requirement page retains the stable requirement identifier FR-COMP-002.

This page is a leaf requirement page and omits a trailing :start from its namespace.

The Statement preserves the approved source intent by requiring Crucible to integrate with Compliance Scanning Tools.

Do not replace integrate with with a narrower behavior such as invoke, execute, load, or receive findings from unless the controlling requirement identifies that specific interaction.

Do not add a particular Compliance Scanning Tool, operating system, scanning standard, protocol, interface, plugin mechanism, data format, scheduling, reporting, or finding-retention obligation unless the controlling requirement changes through an approved requirements process.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-002#Statement&noheader&nofooter&noeditbtn}}

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.