dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001d

This is an old revision of the document!


MO-001d — Security Baseline Conformance

Crucible SHALL create an Infrastructure Environment in conformance with the selected Security Baseline.

This requirement derives from:

The Original Requirement states:

Crucible SHALL enable rapid creation of repeatable, compliant, and secure infrastructure environments.[C1]

MO-001d preserves the portion of the Original Requirement that characterizes an Infrastructure Environment as secure.

The separate requirements derived from MO-001 address:

The Original Requirement uses secure without identifying:

  • The applicable security requirements
  • The controlling Security Baseline
  • The security controls applicable to the Infrastructure Environment
  • The criteria used to determine satisfaction of those controls
  • The Evidence required to support the determination
  • The treatment of security findings or exceptions

The term secure describes a desired quality but does not establish an objectively verifiable condition.

MO-001d:

  • Replaces secure with conformance to an identified Security Baseline
  • Identifies Crucible as the responsible actor
  • Identifies the created Infrastructure Environment as the subject of conformance
  • Identifies the selected Security Baseline as the controlling source of security requirements
  • Separates security conformance from Infrastructure Environment creation, deployment duration, reproducibility, and compliance outcomes

A general claim that an Infrastructure Environment is secure does not identify the security requirements that the environment satisfies.

A selected Security Baseline establishes the applicable security requirements, security controls, configuration settings, assessment criteria, and required Evidence for a defined operational context.

Security Baselines can address:

  • Operating-system hardening
  • Identity and access control
  • Authentication
  • Authorization
  • Privilege management
  • Account configuration
  • Network configuration
  • Service configuration
  • Cryptographic configuration
  • Audit configuration
  • Logging
  • File and directory permissions
  • Software and package restrictions
  • Vulnerability remediation
  • Security monitoring
  • Data protection
  • System integrity

The selected Security Baseline provides the reference against which the Infrastructure Environment is evaluated.

Conformance requires satisfaction of the applicable requirements established by the selected Security Baseline. The existence of a Security Baseline, application of a hardening process, or execution of a security assessment does not alone establish conformance.

Separating Security Baseline conformance from MO-001a permits Crucible to create an Infrastructure Environment successfully while independently passing or failing the applicable security requirements.

This requirement does not establish the applicable Compliance Baseline. MO-001e addresses Compliance Baseline conformance.

Verification confirms that:

  1. The selected Security Baseline is uniquely identified
  2. The selected Security Baseline identifies the security requirements applicable to the Infrastructure Environment
  3. The Infrastructure Environment is evaluated against each applicable security requirement
  4. Each applicable security requirement has a recorded result
  5. The Infrastructure Environment satisfies the conformance criteria established by the selected Security Baseline
  6. Each identified security finding, exception, or deviation is recorded
  7. The generated Evidence supports the conformance determination

Verification includes:

  • Security Baseline inspection
  • Security requirement inspection
  • Security control inspection
  • Security configuration inspection
  • Security assessment
  • Automated security testing
  • Manual security testing
  • Infrastructure state inspection
  • Machine Image inspection
  • Package and software inventory inspection
  • Vulnerability assessment
  • Audit configuration inspection
  • Logging configuration inspection
  • Access-control inspection
  • Security finding inspection
  • Security exception inspection
  • Evidence inspection
  • Provenance inspection
  • Traceability inspection

The verification record identifies:

  1. The selected Security Baseline
  2. The Security Baseline identifier and revision
  3. The Infrastructure Environment under evaluation
  4. The applicable security requirements
  5. The security controls associated with each requirement
  6. The evaluation method applied to each requirement
  7. The result for each applicable security requirement
  8. Each identified security finding
  9. Each approved security exception or deviation
  10. The overall conformance result
  11. The generated Evidence
  12. The applicable Provenance
  13. The applicable Traceability

Phase 1 and subsequent phases

Not Assessed

Implementation status requires evaluation of an Infrastructure Environment created by the current Crucible implementation against the selected Security Baseline.

Draft

This requirement derives from MO-001 in the Crucible System Requirements Specification, Version 1.1 Draft.


This requirement page should retain the stable requirement identifier MO-001d.

This page is a leaf requirement page and omits a trailing :start from its namespace.

Changes to the Statement SHALL preserve the security intent derived from MO-001.

The selected Security Baseline should identify:

  • The Security Baseline identifier
  • The Security Baseline revision
  • The applicable operational context
  • The applicable security requirements
  • The associated security controls
  • The evaluation criteria
  • The permitted exceptions or deviations
  • The required Evidence
  • The conformance determination criteria

Material changes should receive review and should update the related verification criteria, requirements realization, related architecture sections, and source records.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001d#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/01-mission-objectives/mo-001/mo-001d.1784559435.txt.gz
  • Last modified: 2026/07/20 07:57
  • by nick_dido