Crucible SHALL define user-defined Compliance Frameworks.
This requirement derives from:
The Original Requirement states:
The system shall support custom compliance frameworks.[C1]
FR-COMP-007:
No other substantive normalization is required.
Organizations can operate under compliance obligations that extend beyond standardized frameworks such as Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and Federal Risk and Authorization Management Program (FedRAMP) baselines.
User-defined Compliance Frameworks allow an organization to represent compliance criteria derived from:
A user-defined Compliance Framework can organize:
This requirement establishes definition of user-defined Compliance Frameworks without prescribing:
Separate requirements, architecture specifications, workflows, or policies define those subjects and behaviors.
This requirement applies to:
Verification confirms that:
The following pages reference this requirement:
Implemented and Verified
Review and approve FR-COMP-007 as a leaf requirement.
Determine whether Compliance Framework requires a controlled definition in the shared Terms and Definitions corpus.
Determine whether separate requirements govern importing, mapping, approving, publishing, and maintaining user-defined Compliance Frameworks.
Determine whether separate requirements govern deriving Compliance Baselines from user-defined Compliance Frameworks.
This requirement page retains the stable requirement identifier FR-COMP-007.
This page is a leaf requirement page and omits a trailing :start from its namespace.
The Statement preserves the approved source intent by requiring Crucible to define user-defined Compliance Frameworks.
The Statement uses user-defined rather than custom because custom does not identify who establishes the framework or how the framework differs from a predefined framework.
Do not change define to provide, import, maintain, apply, scan against, or assess against unless the controlling requirement identifies that specific behavior.
Do not add framework mapping, approval, publication, version management, scanning, reporting, or Evidence-generation obligations unless the controlling requirement changes through an approved requirements process.
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-007#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.