Table of Contents

FR-COMP-010a — Compliance Finding Transfer Bundle Inclusion

Go to FR-COMP-010 — Transferable Compliance Findings

Statement

Crucible SHALL include Compliance Findings in the Transfer Bundle containing the Artifacts to which the Compliance Findings apply.

Derived From

This requirement derives from:

The Original Requirement states:

The system shall capture compliance findings into the transferable dependency/evidence bundle (see §4.10) so findings from connected build accompany artifacts into disconnected enclave.[C1]

FR-COMP-010a:

Rationale

Compliance Findings describe compliance conditions associated with evaluated Artifacts.

Including the Compliance Findings in the same Transfer Bundle as the affected Artifacts allows the findings to accompany those Artifacts during transfer.

This requirement establishes Transfer Bundle inclusion without requiring Crucible to:

FR-COMP-010b governs preservation of the association between each Compliance Finding and the Artifact to which the finding applies.

Applies To

This requirement applies to:

Verification

Verification confirms that:

  1. One or more Artifacts with associated Compliance Findings are selected for testing
  2. Crucible creates a Transfer Bundle containing the selected Artifacts
  3. Crucible includes the associated Compliance Findings in the same Transfer Bundle
  4. The Compliance Findings can be identified within the resulting Transfer Bundle
  5. The selected Artifacts can be identified within the resulting Transfer Bundle

Referenced By

The following pages reference this requirement:

Implementation Status

Implemented and Verified

Requirement Status

Review and approve FR-COMP-010a as a leaf requirement.


Issues

Determine whether Compliance Finding requires a controlled definition in the shared Terms and Definitions corpus.

Determine whether separate requirements define the representation of Compliance Findings within a Transfer Bundle.

Determine whether separate requirements govern verification of Compliance Findings after Transfer Bundle import.


Notes for Editors

This requirement page retains the derived requirement identifier FR-COMP-010a.

This page is a leaf requirement page and omits a trailing :start from its namespace.

The namespace for this requirement is:

dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010a

The Statement uses the controlling Transfer Bundle namespace:

dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle

The Statement addresses only inclusion of Compliance Findings and their affected Artifacts in the same Transfer Bundle.

FR-COMP-010b governs preservation of the association between each Compliance Finding and the Artifact to which the Compliance Finding applies.

Do not add finding generation, validation, resolution, remediation, reassessment, association-preservation, or compliance-decision obligations unless the controlling requirement changes through an approved requirements process.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010a#Statement&noheader&nofooter&noeditbtn}}

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.