8.2 Perform Compliance Assessments
Go to 8. Compliance Operations
Crucible performs a Compliance Assessment by evaluating an identified subject against the compliance criteria selected in 8.1 Select Compliance Criteria and Baselines.
Crucible integrates with an applicable compliance-scanning tool through an operating-system-independent assessment abstraction. The abstraction separates the compliance operation from a particular scanning product or operating system.
Identify the Assessment Subject
Crucible identifies the subject to evaluate.
An assessment subject can include:
-
A Machine Image
-
A Container Image
-
An Infrastructure Configuration
-
An Infrastructure Environment
-
A deployed resource
-
Another subject supported by the selected Compliance Baseline and assessment provider
The subject remains identifiable throughout the assessment so the assessment result can be associated with the evaluated subject and revision.
Apply the Selected Criteria
The assessment uses the Compliance Baseline and criteria selected for the identified subject.
The assessment inputs identify:
-
The assessment subject
-
The selected Compliance Baseline
-
The applicable criteria
-
The Baseline revision
-
Applicable parameters or tailoring information
-
The selected assessment provider
Crucible does not independently determine which legal, regulatory, contractual, or organizational obligations apply to the subject.
Select the Assessment Provider
Crucible selects an applicable compliance-scanning or assessment tool through the supported provider interface.
The selected provider identifies:
-
The scanning or assessment tool
-
The provider implementation
-
The provider revision
-
The supported subject type
-
The supported operating system
-
The provider-specific parameters
-
The criteria the provider can evaluate
Support for a compliance-scanning tool does not imply that the tool can evaluate every criterion in the selected Compliance Baseline.
Use the Compliance-Scanning Abstraction
The compliance-scanning abstraction defines a common means to invoke supported assessment providers.
The abstraction separates:
-
The identified assessment subject
-
The selected compliance criteria
-
The requested assessment operation
-
Provider-specific invocation details
-
Provider-native results
This separation allows Crucible to integrate with different compliance-scanning tools without defining the compliance workflow around one product-specific interface.
Support Multiple Operating Systems
Crucible supports compliance scanning for multiple operating systems through the compliance-scanning abstraction and applicable provider implementations.
An assessment provider can support:
-
One operating system
-
Multiple operating systems
-
Particular operating-system families
-
Particular versions or distributions
-
Particular subject types
Multiple-operating-system support does not require every provider to support every operating system.
The selected provider must support the operating system and subject type associated with the requested assessment.
Perform the Assessment
Crucible performs the assessment by:
-
Identifying the assessment subject
-
Applying the selected Compliance Baseline and criteria
-
Selecting an applicable assessment provider
-
Supplying the required provider-specific parameters
-
Invoking the assessment provider
-
Receiving the provider-native results
-
Associating the results with the assessed subject and selected criteria
-
Recording the assessment status
The provider performs the provider-specific scanning behavior. Crucible coordinates the assessment and maintains the relationship among the subject, criteria, provider, and returned results.
Handle Unsupported or Incomplete Assessments
Crucible records a condition that prevents the requested assessment from completing.
Such conditions can include:
-
No available provider supports the assessment subject
-
No available provider supports the subject operating system
-
The selected provider cannot evaluate one or more criteria
-
Required provider parameters are unavailable
-
The assessment subject is inaccessible
-
The provider returns an incomplete result
-
The assessment operation fails
Crucible does not treat an incomplete or unsupported assessment as a successful assessment.
Assessment Result
The assessment result identifies:
-
The assessment subject
-
The subject revision
-
The selected Compliance Baseline
-
The applicable criteria
-
The assessment provider
-
The provider revision
-
The provider-specific parameters
-
The provider-native results
-
The assessment status
-
Any unsupported, incomplete, or failed evaluation
The assessment result provides the input used to produce the applicable Compliance Findings, reports, and Evidence under their respective requirements.
Requirements Addressed
| Requirement | Statement |
|---|---|
| FR-COMP-002 — Compliance Scanning Tool Integration |
Crucible SHALL integrate with Compliance Scanning Tools. |
| FR-COMP-008a — Compliance Scanning Abstraction |
Crucible SHALL provide a Compliance Scanning Abstraction. |
| FR-COMP-008b — Multiple Operating-System Support |
Crucible SHALL evaluate two or more Operating Systems against defined compliance criteria. |
The linked leaf requirement pages remain the canonical sources.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.