| Both sides previous revision Previous revision | |
| dido:02-crusible:01-introduction:01-02-scope:start [2026/08/01 04:10] – removed - external edit (Unknown date) 127.0.0.1 | dido:02-crusible:01-introduction:01-02-scope:start [2026/08/01 04:10] (current) – ↷ Page moved and renamed from dido:02-crusible:01-introduction:01-02-scope to dido:02-crusible:01-introduction:01-02-scope:start nick_dido |
|---|
| | ====== 1.2 Scope ====== |
| |
| | [[dido:02-crusible:01-introduction:start|Go to 1. Introduction]] |
| | |
| | [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] addresses the controlled construction, hardening, assessment, transfer, deployment, operation, maintenance, verification, and reproduction of software and [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_environment|Infrastructure Environments]]. |
| | |
| | ===== In Scope ===== |
| | |
| | The scope of Crucible includes: |
| | |
| | * Definition, selection, reuse, and composition of version-controlled [[dido:99_annexes:annex-b-terms-and-definitions:b:baseline|Baselines]] |
| | * Use of [[dido:99_annexes:annex-b-terms-and-definitions:d:declarative_description|Declarative Descriptions]] to identify intended environments, inputs, providers, compliance criteria, and lifecycle operations |
| | * Construction, hardening, signing, verification, promotion, and replacement of [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] |
| | * Construction and management of container images |
| | * Definition and deployment of infrastructure through [[dido:99_annexes:annex-b-terms-and-definitions:i:iac|Infrastructure as Code (IaC)]] |
| | * Separation of provider-independent intent from provider-specific implementation through [[dido:99_annexes:annex-b-terms-and-definitions:p:provider_abstraction|Provider Abstraction]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency_capture|Dependency Capture]] and preservation of [[dido:99_annexes:annex-b-terms-and-definitions:b:build_dependency|Build Dependencies]] in a [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency_store|Dependency Store]] |
| | * Preparation, export, import, and controlled transfer of [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundles]] |
| | * Population of [[dido:99_annexes:annex-b-terms-and-definitions:o:offline_repository|Offline Repositories]] within [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] |
| | * Deployment and validation of infrastructure resources, virtual machines, Kubernetes clusters, containerized workloads, and platform services |
| | * Deployment rollback |
| | * Automated [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_assessment|Compliance Assessment]] using [[dido:99_annexes:annex-b-terms-and-definitions:c:cac|Compliance as Code (CaC)]] |
| | * Generation and preservation of [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_finding|Compliance Findings]], [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]], [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]], and [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] |
| | * Support for security-control implementation Evidence used in Security Control Traceability Matrix, Risk Management Framework, and Authority to Operate activities |
| | * Reproduction of controlled environments from identified inputs and recorded lifecycle information |
| | * Integration with Git-based Workflows, GitOps Workflows, and CI/CD Pipelines |
| | * Access through a Command-Line Interface and a Web-Based User Interface |
| | * Extension through provider, platform, image, compliance, and tooling integration points |
| | |
| | Crucible applies across [[dido:99_annexes:annex-b-terms-and-definitions:c:cloud_environment|Cloud Environments]], [[dido:99_annexes:annex-b-terms-and-definitions:o:on-premises_environment|On-Premises Environments]], [[dido:99_annexes:annex-b-terms-and-definitions:h:hybrid_environment|Hybrid Environments]], [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environments]], [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]], and [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]. |
| | |
| | ===== Out of Scope ===== |
| | |
| | The scope of Crucible does not include: |
| | |
| | * Definition or implementation of the mission-specific functionality that distinguishes a product or delivers its mission value |
| | * Definition of the legal, regulatory, contractual, or organizational criteria governing a particular system or deployment |
| | * Granting [[dido:99_annexes:annex-b-terms-and-definitions:a:accreditation|Accreditation]], [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_approval|Operational Approval]], or an [[dido:99_annexes:annex-b-terms-and-definitions:a:ato|Authority to Operate (ATO)]] |
| | * Replacement of the responsible governance, assessment, compliance, or authorizing authorities |
| | * Mandating a particular cloud provider, infrastructure platform, operating system, compliance scanner, package manager, build tool, or automation technology |
| | * Elimination of product-specific configuration, Baselines, security criteria, provider integrations, or operational decisions |
| | * Assumption of responsibility for product-specific risk acceptance, deployment approval, or operational authorization |
| | |
| | The responsible authorities, standards bodies, policies, contracts, and governance organizations establish the criteria that apply to a particular system or deployment. |
| | |
| | Crucible produces and preserves controlled artifacts, assessment results, Traceability, Provenance, and Evidence that support accreditation, approval, and authorization determinations, but Crucible does not make those determinations. |
| | |
| | Different implementations can use different technologies while preserving the defined architectural contracts, lifecycle controls, Evidence obligations, and provider-independent behavior. |
| | |
| | ---- |
| | |
| | <WRAP centeralign> |
| | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. |
| | </WRAP> |