Crucible SHALL generate Security-Control Implementation Evidence for use in Authorization to Operate (ATO) activities.
This requirement derives from:
The Original Requirement states:
FR-COMP-009c:
An Authorization to Operate (ATO) records a risk-based management decision by an Authorizing Authority to permit a system to operate within a defined scope and to accept the associated residual risk.
Security-Control Implementation Evidence provides information that an Authorizing Authority and supporting participants can review when evaluating the implementation of Security Controls and the security posture of a system.
This requirement establishes generation of Security-Control Implementation Evidence for use in ATO activities without requiring Crucible to:
Separate requirements, authorization procedures, evidence profiles, and governance processes govern those subjects and responsibilities.
This requirement applies to:
Verification confirms that:
The following pages reference this requirement:
Implemented and Verified
Review and approve FR-COMP-009c as a leaf requirement.
Determine whether Security Control requires a controlled definition in the shared Terms and Definitions corpus.
Determine whether Security-Control Implementation Evidence requires a controlled definition in the shared Terms and Definitions corpus.
Determine whether separate requirements define the minimum identifiers, provenance, and references required for Evidence used in ATO activities.
Determine whether separate requirements identify the ATO activities for which Crucible must generate Evidence.
This requirement page retains the derived requirement identifier FR-COMP-009c.
This page is a leaf requirement page and omits a trailing :start from its namespace.
The namespace for this requirement is:
dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-009:fr-comp-009c
The Statement addresses only generation of Security-Control Implementation Evidence for use in Authorization to Operate activities.
FR-COMP-009a governs Evidence generated for inclusion in a Security Control Traceability Matrix.
FR-COMP-009b governs Evidence generated for use in Risk Management Framework activities.
This requirement does not assign authorization or risk-acceptance responsibilities to Crucible. The Authorizing Authority remains responsible for evaluating the available information, accepting residual risk, and issuing or denying an ATO.
Do not add Security Control approval, assessment authority, risk acceptance, authorization, ATO issuance, or operational approval responsibilities unless the controlling requirement changes through an approved requirements process.
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-009:fr-comp-009c#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.