6.1 Construct and Assess the Environment
Within a Connected Environment, Crucible constructs controlled Images and assesses identified subjects against applicable compliance criteria.
Connectivity provides access to the authorized resources required by the applicable construction and assessment activities. The Image Management and Compliance Management requirements define the capabilities performed. Connected operation does not establish a separate source-access capability.
Prepare the Controlled Inputs
Crucible uses the applicable controlled inputs for the selected construction or assessment activity.
Construction inputs can include:
-
A selected Baseline Composition
-
A base Machine Image or Container Image
-
Selected Image Layers
-
Application content
-
Software packages
-
Configuration definitions
-
Security configuration
-
Build dependencies
-
Applicable build parameters
Assessment inputs can include:
-
The identified assessment subject
-
The applicable Compliance Baseline
-
Compliance criteria
-
Assessment content
-
The selected assessment provider
-
Provider-specific parameters
The applicable lifecycle definition identifies the inputs required for each activity.
Construct the Image
Crucible constructs an identified Machine Image or Container Image from the selected controlled inputs.
The construction activity can include:
-
Select the applicable image form
-
Select the controlled build inputs
-
Execute the applicable construction process
-
Produce the resulting Image
-
Assign the Image identifier and revision
-
Record the Image content digest
-
Sign the Image when required
-
Verify the Image signature when required
-
Apply the applicable promotion transition
When a required change affects a deployed immutable Image, Crucible constructs a replacement Image rather than modifying the deployed Image in place.
Image construction does not independently establish compliance or authorization for deployment.
Select the Compliance Criteria
Crucible identifies the compliance criteria applicable to the assessment subject.
The criteria can derive from:
-
A Compliance Baseline
-
A DISA STIG Compliance Baseline
-
A FedRAMP Baseline
-
A custom compliance framework
-
Another approved set of compliance criteria
The responsible organization determines which compliance criteria apply to the assessment subject.
Perform the Compliance Assessment
Crucible integrates with an applicable compliance-scanning or assessment tool and evaluates the identified subject against the selected compliance criteria.
The assessment activity can include:
-
Identify the assessment subject
-
Select the applicable Compliance Baseline or criteria
-
Select the assessment provider
-
Supply the required assessment parameters
-
Execute the assessment
-
Receive the assessment results
-
Produce the applicable Compliance Findings
-
Generate the compliance report
-
Generate the Compliance Evidence Artifacts
The compliance-scanning abstraction separates the assessment activity from a particular operating system or scanning product.
Support for multiple operating systems does not require every assessment provider to support every operating system.
Review the Assessment Results
The assessment result identifies the relationship between the assessed subject and the applicable compliance criteria.
The result can include:
-
The assessed subject and revision
-
The selected Compliance Baseline or criteria
-
The assessment provider
-
The assessment results
-
Compliance Findings
-
The compliance report
-
Compliance Evidence Artifacts
-
Security-control implementation Evidence
-
Transferable Compliance Findings, when applicable
Crucible generates Evidence that can support Security Control Traceability Matrix, Risk Management Framework, and Authority to Operate activities.
Crucible does not grant Accreditation, Operational Approval, risk acceptance, or an Authority to Operate.
Connected-Operation Result
The connected construction and assessment activities produce identifiable results that can include:
-
A constructed Machine Image or Container Image
-
An Image identifier and revision
-
An Image content digest
-
A Digital Signature
-
A signature-verification result
-
An Image promotion result
-
Compliance Findings
-
A compliance report
-
Compliance Evidence Artifacts
-
Security-control implementation Evidence
-
Transferable Compliance Findings
The applicable lifecycle activity determines which results Crucible produces.
Requirements Addressed
The linked leaf requirement pages remain the canonical sources.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.