Table of Contents

FR-COMP-010b — Compliance Finding Association Preservation

Go to FR-COMP-010 — Transferable Compliance Findings

Statement

Crucible SHALL preserve the association between each Compliance Finding and the Artifact to which the Compliance Finding applies when transferring them in a Transfer Bundle from a Connected Environment to a Disconnected Environment.

Derived From

This requirement derives from:

The Original Requirement states:

The system shall capture compliance findings into the transferable dependency/evidence bundle (see §4.10) so findings from connected build accompany artifacts into disconnected enclave.[C1]

FR-COMP-010b:

Rationale

A Compliance Finding remains useful after transfer only when its association with the evaluated Artifact remains identifiable.

Preserving this association enables actors and processes in a Disconnected Environment to determine which Compliance Findings apply to each transferred Artifact.

FR-COMP-010a governs inclusion of Compliance Findings and affected Artifacts in the same Transfer Bundle. This requirement governs preservation of the association between them.

This requirement does not require Crucible to:

Applies To

This requirement applies to:

Verification

Verification confirms that:

  1. An Artifact with one or more associated Compliance Findings is selected for testing
  2. Crucible includes the selected Artifact and its associated Compliance Findings in a Transfer Bundle
  3. Crucible transfers the Transfer Bundle from a Connected Environment to a Disconnected Environment
  4. The transferred Artifact can be identified in the Disconnected Environment
  5. Each transferred Compliance Finding can be identified in the Disconnected Environment
  6. The association between each transferred Compliance Finding and the Artifact to which it applies can be determined in the Disconnected Environment

Referenced By

The following pages reference this requirement:

Implementation Status

Implemented and Verified

Requirement Status

Review and approve FR-COMP-010b as a leaf requirement.


Issues

Confirm the controlled definition of Compliance Finding in the shared Terms and Definitions corpus.

Determine whether separate requirements define the identifier or reference mechanism used to preserve the association between a Compliance Finding and an Artifact.

Determine whether separate requirements govern verification of the preserved association after Transfer Bundle import.


Notes for Editors

This requirement page retains the derived requirement identifier FR-COMP-010b.

This page is a leaf requirement page and omits a trailing :start from its namespace.

The Statement addresses only preservation of the association between each Compliance Finding and the Artifact to which the Compliance Finding applies during transfer between Connected and Disconnected Environments.

FR-COMP-010a governs inclusion of Compliance Findings and affected Artifacts in the same Transfer Bundle.

Use the following controlling Terms and Definitions entry for Compliance Finding:

Do not add finding generation, validation, resolution, remediation, reassessment, identifier-format, or compliance-decision obligations unless the controlling requirement changes through an approved requirements process.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010b#Statement&noheader&nofooter&noeditbtn}}

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.