Show pageOld revisionsBacklinksAdd to bookExport to PDFODT exportBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== 8. Compliance Operations ====== [[dido:02-crusible:start|Go to Crucible]] Compliance Operations describe how [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] applies selected compliance criteria to identified subjects, produces [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_finding|Compliance Findings]], generates supporting [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]], and transfers supported compliance information between operational environments. The compliance lifecycle includes: * Selecting the applicable compliance criteria and [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_baseline|Compliance Baselines]] * Identifying the subject of the assessment * Selecting and invoking an applicable assessment provider * Evaluating the subject against the selected criteria * Producing Compliance Findings * Generating Compliance Evidence Artifacts * Producing security-control implementation Evidence * Including applicable Compliance Findings in a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] * Preserving required associations between transferred findings and the subjects they describe Compliance Operations support organizational review, remediation, security-control evaluation, audit, Risk Management Framework activities, and Authority to Operate processes. Crucible generates and associates compliance information as required by the applicable leaf requirements. Crucible does not independently determine which legal, regulatory, contractual, or organizational criteria apply, and Crucible does not grant Accreditation, Operational Approval, risk acceptance, or an Authority to Operate. The child pages distinguish among: * Selection of compliance criteria * Execution of a Compliance Assessment * Production of Compliance Findings * Generation or preservation of supporting Evidence to the extent required * Transfer of Compliance Findings and associated information The applicable leaf requirements in [[dido:02-crusible:99-annexes:annex-c-requirements:start|Annex C: Requirements]] define the required behavior. A child page SHALL NOT claim Evidence retention, repository storage, retrieval, lifecycle-record preservation, or broader traceability unless an approved leaf requirement explicitly establishes that capability. ===== Contents ===== {{indexmenu>dido:02-crusible:08-compliance-and-authorization-operations#1|js navbar nocookie maxjs#2 id#crucible_compliance_operations_nav}} ===== Notes for Editors ===== The title of each child page must remain consistent with the behavior supported by its applicable leaf requirements. In particular, generation of Compliance Evidence Artifacts does not by itself establish preservation, retention, storage, or retrieval requirements. The scope and title of 8.4 must be reviewed against the approved Evidence-related leaf Statements before that page is finalized. Requirements remain canonical in [[dido:02-crusible:99-annexes:annex-c-requirements:start|Annex C: Requirements]] and SHALL NOT be duplicated on these pages. ---- <WRAP centeralign> © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. </WRAP> dido/02-crusible/08-compliance-and-authorization-operations/start.txt Last modified: 2026/08/01 07:36by nick_dido