Crucible SHALL provide Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) Compliance Baselines.
This requirement derives from:
The Original Requirement states:
FR-COMP-005:
No other substantive normalization is required.
The Defense Information Systems Agency (DISA) publishes Security Technical Implementation Guides (STIGs) that provide security configuration guidance and associated evaluation criteria for specified technologies.
A DISA STIG Compliance Baseline enables Crucible compliance activities to use criteria derived from an identified STIG.
Such a Compliance Baseline can include:
This requirement establishes provision of DISA STIG Compliance Baselines without prescribing:
Separate requirements, architecture specifications, workflows, or policies define those subjects and behaviors.
This requirement applies to:
Verification confirms that:
The following pages reference this requirement:
Implemented and Verified
Review and approve FR-COMP-005 as a leaf requirement.
Determine whether separate requirements identify the DISA STIG products and revisions that Crucible must provide.
Determine whether separate requirements govern importing, updating, approving, and applying DISA STIG Compliance Baselines.
This requirement page retains the stable requirement identifier FR-COMP-005.
This page is a leaf requirement page and omits a trailing :start from its namespace.
The Statement preserves the approved source intent by requiring Crucible to provide DISA STIG Compliance Baselines.
Use the following controlling Terms and Definitions entries:
Do not change provide to define, import, maintain, apply, scan against, or assess against unless the controlling requirement identifies that specific behavior.
Do not add a particular STIG, STIG revision, operating system, scanning tool, update mechanism, remediation process, reporting obligation, or Evidence-generation obligation unless the controlling requirement changes through an approved requirements process.
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-005#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.