This is an old revision of the document!
MO-001d — Security Baseline Conformance
Statement
Crucible SHALL create an Infrastructure Environment in conformance with the selected Security Baseline.
Derived From
This requirement derives from:
The Original Requirement states:
Crucible SHALL enable rapid creation of repeatable, compliant, and secure infrastructure environments.[C1]
MO-001d preserves the portion of the Original Requirement that characterizes an Infrastructure Environment as secure.
The separate requirements derived from MO-001 address:
Assessment
The Original Requirement uses secure without identifying:
-
The applicable security requirements
-
The controlling Security Baseline
-
The security controls applicable to the Infrastructure Environment
-
The criteria used to determine satisfaction of those controls
-
The Evidence required to support the determination
-
The treatment of security findings or exceptions
The term secure describes a desired quality but does not establish an objectively verifiable condition.
MO-001d:
-
Replaces secure with conformance to an identified Security Baseline
-
Identifies Crucible as the responsible actor
-
Identifies the created Infrastructure Environment as the subject of conformance
-
Identifies the selected Security Baseline as the controlling source of security requirements
-
Separates security conformance from Infrastructure Environment creation, deployment duration, reproducibility, and compliance outcomes
Rationale
A general claim that an Infrastructure Environment is secure does not identify the security requirements that the environment satisfies.
A selected Security Baseline establishes the applicable security requirements, security controls, configuration settings, assessment criteria, and required Evidence for a defined operational context.
Security Baselines can address:
-
Operating-system hardening
-
Identity and access control
-
Authentication
-
Authorization
-
Privilege management
-
Account configuration
-
Network configuration
-
Service configuration
-
Cryptographic configuration
-
Audit configuration
-
Logging
-
File and directory permissions
-
Software and package restrictions
-
Vulnerability remediation
-
Security monitoring
-
Data protection
-
System integrity
The selected Security Baseline provides the reference against which the Infrastructure Environment is evaluated.
Conformance requires satisfaction of the applicable requirements established by the selected Security Baseline. The existence of a Security Baseline, application of a hardening process, or execution of a security assessment does not alone establish conformance.
Separating Security Baseline conformance from MO-001a permits Crucible to create an Infrastructure Environment successfully while independently passing or failing the applicable security requirements.
This requirement does not establish the applicable Compliance Baseline. MO-001e addresses Compliance Baseline conformance.
Applies To
This requirement applies to:
-
Security requirements
-
Security controls
-
Security configurations
-
Security assessments
-
Security findings
-
Security exceptions
Verification
Verification confirms that:
-
The selected Security Baseline is uniquely identified
-
The selected Security Baseline identifies the security requirements applicable to the Infrastructure Environment
-
The Infrastructure Environment is evaluated against each applicable security requirement
-
Each applicable security requirement has a recorded result
-
The Infrastructure Environment satisfies the conformance criteria established by the selected Security Baseline
-
Each identified security finding, exception, or deviation is recorded
-
The generated Evidence supports the conformance determination
Verification includes:
-
Security Baseline inspection
-
Security requirement inspection
-
Security control inspection
-
Security configuration inspection
-
Security assessment
-
Automated security testing
-
Manual security testing
-
Infrastructure state inspection
-
Machine Image inspection
-
Package and software inventory inspection
-
Vulnerability assessment
-
Audit configuration inspection
-
Logging configuration inspection
-
Access-control inspection
-
Security finding inspection
-
Security exception inspection
-
Evidence inspection
-
Provenance inspection
-
Traceability inspection
The verification record identifies:
-
The selected Security Baseline
-
The Security Baseline identifier and revision
-
The Infrastructure Environment under evaluation
-
The applicable security requirements
-
The security controls associated with each requirement
-
The evaluation method applied to each requirement
-
The result for each applicable security requirement
-
Each identified security finding
-
Each approved security exception or deviation
-
The overall conformance result
-
The generated Evidence
-
The applicable Provenance
-
The applicable Traceability
Requirements Realized By
This requirement is realized by:
Related Architecture Sections
Referenced By
The following pages reference this requirement:
Delivery Phase
Phase 1 and subsequent phases
Implementation Status
Not Assessed
Implementation status requires evaluation of an Infrastructure Environment created by the current Crucible implementation against the selected Security Baseline.
Requirement Status
Draft
This requirement derives from MO-001 in the Crucible System Requirements Specification, Version 1.1 Draft.
Notes for Editors
This requirement page should retain the stable requirement identifier MO-001d.
This page is a leaf requirement page and omits a trailing :start from its namespace.
Changes to the Statement SHALL preserve the security intent derived from MO-001.
The selected Security Baseline should identify:
-
The Security Baseline identifier
-
The Security Baseline revision
-
The applicable operational context
-
The applicable security requirements
-
The associated security controls
-
The evaluation criteria
-
The permitted exceptions or deviations
-
The required Evidence
-
The conformance determination criteria
Material changes should receive review and should update the related verification criteria, requirements realization, related architecture sections, and source records.
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001d#Statement&noheader&nofooter&noeditbtn}}
Do not rename this page after an external citation unless a redirect or move plan is in place.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.