MO-001d — Security Baseline Conformance

Crucible SHALL create an Infrastructure Environment that conforms to the selected Security Baseline.

This requirement derives from:

The Original Requirement states:

Crucible SHALL enable rapid creation of repeatable, compliant, and secure infrastructure environments.[C1]

MO-001d preserves the portion of the Original Requirement that characterizes Infrastructure Environments as secure by requiring each created Infrastructure Environment to conform to the selected Security Baseline.

The separate requirements derived from MO-001 address:

The word secure does not establish an objective security obligation unless a controlling Security Baseline identifies the required security controls and conformance criteria.

The selected Security Baseline provides the controlled security requirements against which the created Infrastructure Environment is evaluated.

Security Baseline conformance supports:

  • Consistent application of required security controls
  • Objective evaluation of the created Infrastructure Environment
  • Identification of unmet or incorrectly implemented controls
  • Evidence generation
  • Independent review of security outcomes

Separating Security Baseline conformance from Infrastructure Environment creation permits Crucible to create an Infrastructure Environment while independently passing or failing the security requirement.

This requirement does not establish a deployment-duration threshold, reproducibility criterion, or Compliance Baseline. The other requirements derived from MO-001 address those outcomes.

Verification confirms that:

  1. The selected Security Baseline is identified
  2. The Security Baseline identifies the security controls and conformance criteria used for evaluation
  3. The created Infrastructure Environment is evaluated against the selected Security Baseline
  4. Each required security control is evaluated
  5. The created Infrastructure Environment satisfies the conformance criteria defined by the selected Security Baseline
  6. Any security finding is identified and associated with the affected security control
  7. The verification record preserves Traceability among the selected Security Baseline, the evaluated security controls, the created Infrastructure Environment, and the evaluation result

Implemented and Verified

Assess whether the current Crucible implementation creates Infrastructure Environments that conform to the selected Security Baseline.

Review and accept MO-001d as a proposed derived requirement created from the evaluation and decomposition of MO-001 in the Crucible System Requirements Specification, Version 1.1 Draft.


The following unresolved issues affect this requirement:

Identify the controlling source that selects the Security Baseline for each Infrastructure Environment.

Identify the security controls and conformance criteria that determine Security Baseline conformance.

Define how exceptions, deviations, waivers, and compensating controls affect Security Baseline conformance.

Define whether an Infrastructure Environment with unresolved security findings can satisfy this requirement.


This requirement page should retain the stable requirement identifier MO-001d.

This page is a leaf requirement page and omits a trailing :start from its namespace.

The parent MO-001 page is a non-leaf page and retains a trailing :start in its namespace.

Changes to the Statement should preserve:

The unresolved Security Baseline selection and conformance criteria should remain recorded in the Issues section until a controlling source resolves them.

Material changes should receive review and should update the verification criteria, source records, and Issues section.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001d#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/01-mission-objectives/mo-001/mo-001d.txt
  • Last modified: 2026/07/30 05:20
  • by nick_dido