8.2 Perform Compliance Assessments

Go to 8. Compliance Operations

Crucible performs a Compliance Assessment by evaluating an identified subject against the compliance criteria selected in 8.1 Select Compliance Criteria and Baselines.

Crucible integrates with an applicable compliance-scanning tool through an operating-system-independent assessment abstraction. The abstraction separates the compliance operation from a particular scanning product or operating system.

Crucible identifies the subject to evaluate.

An assessment subject can include:

  • A Machine Image
  • A Container Image
  • An Infrastructure Configuration
  • An Infrastructure Environment
  • A deployed resource
  • Another subject supported by the selected Compliance Baseline and assessment provider

The subject remains identifiable throughout the assessment so the assessment result can be associated with the evaluated subject and revision.

The assessment uses the Compliance Baseline and criteria selected for the identified subject.

The assessment inputs identify:

  • The assessment subject
  • The selected Compliance Baseline
  • The applicable criteria
  • The Baseline revision
  • Applicable parameters or tailoring information
  • The selected assessment provider

Crucible does not independently determine which legal, regulatory, contractual, or organizational obligations apply to the subject.

Crucible selects an applicable compliance-scanning or assessment tool through the supported provider interface.

The selected provider identifies:

  • The scanning or assessment tool
  • The provider implementation
  • The provider revision
  • The supported subject type
  • The supported operating system
  • The provider-specific parameters
  • The criteria the provider can evaluate

Support for a compliance-scanning tool does not imply that the tool can evaluate every criterion in the selected Compliance Baseline.

The compliance-scanning abstraction defines a common means to invoke supported assessment providers.

The abstraction separates:

  • The identified assessment subject
  • The selected compliance criteria
  • The requested assessment operation
  • Provider-specific invocation details
  • Provider-native results

This separation allows Crucible to integrate with different compliance-scanning tools without defining the compliance workflow around one product-specific interface.

Crucible supports compliance scanning for multiple operating systems through the compliance-scanning abstraction and applicable provider implementations.

An assessment provider can support:

  • One operating system
  • Multiple operating systems
  • Particular operating-system families
  • Particular versions or distributions
  • Particular subject types

Multiple-operating-system support does not require every provider to support every operating system.

The selected provider must support the operating system and subject type associated with the requested assessment.

Crucible performs the assessment by:

  1. Identifying the assessment subject
  2. Applying the selected Compliance Baseline and criteria
  3. Selecting an applicable assessment provider
  4. Supplying the required provider-specific parameters
  5. Invoking the assessment provider
  6. Receiving the provider-native results
  7. Associating the results with the assessed subject and selected criteria
  8. Recording the assessment status

The provider performs the provider-specific scanning behavior. Crucible coordinates the assessment and maintains the relationship among the subject, criteria, provider, and returned results.

Crucible records a condition that prevents the requested assessment from completing.

Such conditions can include:

  • No available provider supports the assessment subject
  • No available provider supports the subject operating system
  • The selected provider cannot evaluate one or more criteria
  • Required provider parameters are unavailable
  • The assessment subject is inaccessible
  • The provider returns an incomplete result
  • The assessment operation fails

Crucible does not treat an incomplete or unsupported assessment as a successful assessment.

The assessment result identifies:

  • The assessment subject
  • The subject revision
  • The selected Compliance Baseline
  • The applicable criteria
  • The assessment provider
  • The provider revision
  • The provider-specific parameters
  • The provider-native results
  • The assessment status
  • Any unsupported, incomplete, or failed evaluation

The assessment result provides the input used to produce the applicable Compliance Findings, reports, and Evidence under their respective requirements.

Requirement Statement
FR-COMP-002 — Compliance Scanning Tool Integration

Crucible SHALL integrate with Compliance Scanning Tools.

FR-COMP-008a — Compliance Scanning Abstraction

Crucible SHALL provide a Compliance Scanning Abstraction.

FR-COMP-008b — Multiple Operating-System Support

Crucible SHALL evaluate two or more Operating Systems against defined compliance criteria.

The linked leaf requirement pages remain the canonical sources.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/08-compliance-and-authorization-operations/08-02-perform-compliance-assessments.txt
  • Last modified: 2026/08/01 07:27
  • by nick_dido