dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001e

This is an old revision of the document!


MO-001e — Compliance Baseline Conformance

Crucible SHALL create an Infrastructure Environment in conformance with the selected Compliance Baseline.

This requirement derives from:

The Original Requirement states:

Crucible SHALL enable rapid creation of repeatable, compliant, and secure infrastructure environments.[C1]

MO-001e preserves the portion of the Original Requirement that characterizes an Infrastructure Environment as compliant.

The separate requirements derived from MO-001 address:

The Original Requirement uses compliant without identifying:

  • The applicable compliance requirements
  • The controlling Compliance Baseline
  • The criteria used to determine satisfaction of the applicable requirements
  • The assessment methods applied to the Infrastructure Environment
  • The Evidence required to support the determination
  • The treatment of Compliance Findings, exceptions, or deviations

The term compliant describes a desired condition but does not establish an objectively verifiable requirement.

MO-001e:

  • Replaces compliant with conformance to an identified Compliance Baseline
  • Identifies Crucible as the responsible actor
  • Identifies the created Infrastructure Environment as the subject of conformance
  • Identifies the selected Compliance Baseline as the controlling source of compliance requirements
  • Separates Compliance Baseline conformance from Infrastructure Environment creation, deployment duration, reproducibility, and security outcomes

A general claim that an Infrastructure Environment is compliant does not identify the requirements the environment satisfies.

A selected Compliance Baseline establishes the applicable requirements, assessment criteria, evaluation methods, required Evidence, and conformance determination criteria for a defined operational context.

Compliance Baselines can address:

  • Statutory requirements
  • Regulatory requirements
  • Contractual requirements
  • Organizational policies
  • Technical standards
  • Configuration standards
  • Security implementation guidance
  • Operational controls
  • Documentation requirements
  • Evidence requirements
  • Reporting requirements
  • Retention requirements
  • Traceability requirements
  • Approval requirements

The selected Compliance Baseline provides the reference against which the Infrastructure Environment is evaluated.

Conformance requires satisfaction of the applicable requirements established by the selected Compliance Baseline. Selection of a Compliance Baseline, execution of a Compliance Assessment, or generation of Evidence does not alone establish conformance.

Separating Compliance Baseline conformance from MO-001a permits Crucible to create an Infrastructure Environment successfully while independently passing or failing the applicable compliance requirements.

This requirement does not establish the applicable Security Baseline. MO-001d addresses Security Baseline conformance.

Verification confirms that:

  1. The selected Compliance Baseline is uniquely identified
  2. The selected Compliance Baseline identifies the requirements applicable to the Infrastructure Environment
  3. The Infrastructure Environment is evaluated against each applicable requirement
  4. Each applicable requirement has a recorded result
  5. The Infrastructure Environment satisfies the conformance criteria established by the selected Compliance Baseline
  6. Each identified Compliance Finding, exception, or deviation is recorded
  7. The generated Evidence supports the conformance determination

Verification includes:

  • Compliance Baseline inspection
  • Compliance requirement inspection
  • Compliance control inspection
  • Automated compliance testing
  • Manual compliance testing
  • Infrastructure state inspection
  • Machine Image inspection
  • Package and software inventory inspection
  • Configuration inspection
  • Documentation inspection
  • Evidence inspection
  • Compliance Finding inspection
  • Compliance exception inspection
  • Provenance inspection
  • Traceability inspection

The verification record identifies:

  1. The selected Compliance Baseline
  2. The Compliance Baseline identifier and revision
  3. The Infrastructure Environment under evaluation
  4. The applicable compliance requirements
  5. The controls associated with each requirement
  6. The evaluation method applied to each requirement
  7. The result for each applicable compliance requirement
  8. Each identified Compliance Finding
  9. Each approved compliance exception or deviation
  10. The overall conformance result
  11. The generated Evidence
  12. The applicable Provenance
  13. The applicable Traceability

Phase 1 and subsequent phases

Not Assessed

Implementation status requires evaluation of an Infrastructure Environment created by the current Crucible implementation against the selected Compliance Baseline.

Draft

This requirement derives from MO-001 in the Crucible System Requirements Specification, Version 1.1 Draft.


This requirement page should retain the stable requirement identifier MO-001e.

This page is a leaf requirement page and omits a trailing :start from its namespace.

Changes to the Statement SHALL preserve the compliance intent derived from MO-001.

The selected Compliance Baseline should identify:

  • The Compliance Baseline identifier
  • The Compliance Baseline revision
  • The applicable operational context
  • The applicable compliance requirements
  • The associated controls
  • The evaluation criteria
  • The permitted exceptions or deviations
  • The required Evidence
  • The conformance determination criteria

Material changes should receive review and should update the related verification criteria, requirements realization, related architecture sections, and source records.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:mo-001e#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/01-mission-objectives/mo-001/mo-001e.1784559553.txt.gz
  • Last modified: 2026/07/20 07:59
  • by nick_dido