dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:start

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:start [2026/07/15 11:55] nick_didodido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001:start [2026/07/22 08:51] (current) nick_dido
Line 1: Line 1:
-====== MO-001 ======+====== MO-001 — Repeatable, Compliant, and Secure Infrastructure Environments ======
  
-[[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:start|Go to C.1 Mission Objectives]]+[[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:start|Go to Mission Objectives]]
  
-===== Statement =====+===== Original Requirement =====
  
-Crucible SHALL:+> //Crucible SHALL enable rapid creation of repeatable, compliant, and secure infrastructure environments.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
  
-  - Create an infrastructure environment from controlled [[dido:99_annexes:annex-b-terms-and-definitions:d:declarative_description|declarative inputs]] and reusable baselines within the applicable deployment-time criteria +===== Assessment of Original Requirement =====
-  - Reproduce an equivalent infrastructure environment from equivalent controlled inputs within defined comparison criteria +
-  - Apply the security controls required by the selected security baseline +
-  - Satisfy the acceptance criteria defined by the selected compliance baseline+
  
-===== Source Statement ===== +The Original Requirement preserves the approved mission objective but does not express independently testable normative statements.
- +
-> Crucible SHALL enable rapid creation of repeatable, compliant, and secure infrastructure environments. +
- +
-===== Source ===== +
- +
-Crucible System Requirements Specification, Version 1.1 Draft, Section 2, Mission Objectives, MO-001. +
- +
-===== Assessment ===== +
- +
-The source statement expresses the approved mission objective but does not provide a fully testable requirement formulation.+
  
 The following Specification Discipline and Authoring findings apply: The following Specification Discipline and Authoring findings apply:
  
-  * The verb **enable** identifies facilitation rather than the behavior Crucible performs +  * **Enable** is a weak verb that describes facilitation rather than an observable behavior performed by [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] 
-  * The qualifier **rapid** does not identify a duration, threshold, baseline, or comparison method +  * **Rapid** does not identify a duration, threshold, baseline, or comparison method 
-  * The terms **repeatable**, **compliant**, and **secure** identify separate outcomes that require independently defined criteria +  * **Repeatable** does not identify the [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]] or comparison criteria required to determine equivalence 
-  * The source statement combines multiple independently verifiable obligations+  * **Compliant** does not identify the [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_baseline|Compliance Baseline]] or acceptance criteria 
 +  * **Secure** does not identify the [[dido:99_annexes:annex-b-terms-and-definitions:s:security_baseline|Security Baseline]] or required security controls
  
-The normalized Statement separates the obligations while preserving the intent of the source statement.+The Original Requirement combines the following independently testable outcomes:
  
-===== Rationale =====+  * Infrastructure Environment creation 
 +  * Deployment duration 
 +  * Repeatability 
 +  * Compliance 
 +  * Security
  
-Organizations often require substantial manual effort to construct infrastructure environmentsapply security configurationsvalidate complianceand reproduce the resulting environments.+The Original Requirement does not identify the Controlled Inputsbaselinesthresholdsor evaluation criteria required to verify these outcomes.
  
-Crucible reduces this effort by coordinating:+The Original Requirement therefore requires:
  
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:declarative_description|Declarative Descriptions]] +  * Replacement of **enable** with observable Crucible behavior 
-  * Reusable baselines +  * Definition of the duration or performance criterion represented by **rapid** 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] construction +  * Identification of the Controlled Inputs and comparison criteria used to determine repeatability 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:i:iac|Infrastructure as Code (IaC)]] +  * Identification of the Compliance Baseline and acceptance criteria used to determine compliance 
-  * Infrastructure deployment +  * Identification of the Security Baseline and required controls used to determine security 
-  * Compliance assessment +  * Separation of the independently testable outcomes 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] generation +  * Confirmation that the derived requirements collectively preserve the complete intent of MO-001
-  * Controlled and repeatable workflows+
  
-The resulting process supports [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]], security control application, and compliance evaluation across connected and disconnected operational environments.+The decomposition preserves ''MO-001'' as the stable parent requirement identifier. Each proposed replacement requirement receives a lettered identifier and a separate leaf requirement page.
  
-===== Applies To =====+===== Proposed Statements =====
  
-This requirement applies to:+The Original Requirement is decomposed into independently identifiable proposed replacement requirements:
  
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:declarative_description|Crucible Descriptions]] +{{indexmenu>dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-001#1|js navbar nocookie maxjs#1 id#crucible_mo_001_requirements_nav}}
-  * [[dido:02-crusible:05-descriptions-composition-and-baselines:05-3-baseline-composition|Baseline composition]] +
-  * Image-layer baselines +
-  * Infrastructure baselines +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] construction +
-  * [[dido:02-crusible:07-infrastructure-and-deployment:07-3-infrastructure-deployment|Infrastructure deployment]] +
-  * [[dido:02-crusible:07-infrastructure-and-deployment:07-4-provisioning|Provisioning]] +
-  * [[dido:02-crusible:09-compliance-and-security:09-6-scan-normalize-and-remediate|Compliance assessment]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environments]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]] +
-  * CI/CD pipeline integration +
-  * [[dido:02-crusible:12-operational-lifecycle:start|Operational lifecycle management]]+
  
-===== Verification =====+===== Requirement Status =====
  
-  - Verification SHALL confirm that Crucible creates an infrastructure environment from controlled [[dido:99_annexes:annex-b-terms-and-definitions:d:declarative_description|declarative inputs]] and reusable baselines within the deployment-time criteria defined for the applicable test. +<todo>Review and approve the proposed decomposition of MO-001 into independently testable requirements.</todo>
-  - Verification SHALL confirm that repeated execution with equivalent controlled inputs produces equivalent infrastructure environments according to defined comparison criteria. +
-  - Verification SHALL confirm that the creation workflow applies the security controls required by the selected security baseline. +
-  - Verification SHALL confirm that the resulting environment satisfies the acceptance criteria defined by the selected compliance baseline.+
  
-Verification may include:+<todo>Determine whether the child requirements under MO-001 collectively supersede MO-001.</todo>
  
-  * Baseline-composition tests +<todo>If the child requirements are accepted as the complete replacement for MO-001, mark MO-001 as superseded and preserve this page as the parent Traceability record.</todo>
-  * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] build tests +
-  * Infrastructure-deployment tests +
-  * Compliance-scan tests +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]-generation tests +
-  * Repeated-build comparisons +
-  * Repeated-deployment comparisons +
-  * Connected and disconnected workflow demonstrations +
-  * End-to-end CI/CD pipeline tests+
  
-The verification record SHALL identify:+---- 
 +===== Issues =====
  
-  * The controlled inputs +The following unresolved issues affect the decomposition of MO-001:
-  * The applicable deployment-time criteria +
-  * The environment-comparison criteria +
-  * The selected security baseline +
-  * The selected compliance baseline +
-  * The observed results +
-  * The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]+
  
-===== Traceability =====+<todo>Define the duration, threshold, baseline, and measurement method represented by rapid.</todo>
  
-This requirement supports:+<todo>Identify the Controlled Inputs and comparison criteria used to determine whether Infrastructure Environments are repeatable.</todo>
  
-  * FR-CFG-001 through FR-CFG-005 +<todo>Identify the Compliance Baseline and acceptance criteria used to determine whether an Infrastructure Environment is compliant.</todo>
-  * FR-IMG-001 through FR-IMG-006 +
-  * FR-DEP-001 through FR-DEP-007 +
-  * FR-AG-001 through FR-AG-005 +
-  * FR-COMP-001 through FR-COMP-010 +
-  * FR-DSO-001 through FR-DSO-006 +
-  * FR-BAS-001 through FR-BAS-004 +
-  * FR-DEPC-001 through FR-DEPC-005 +
-  * KVP-001 +
-  * KVP-003 +
-  * KVP-004 +
-  * KVP-005+
  
-This requirement also relates to:+<todo>Identify the Security Baseline and required controls used to determine whether an Infrastructure Environment is secure.</todo>
  
-  * [[dido:02-crusible:05-descriptions-composition-and-baselines:start|5. Descriptions, Composition, and Baselines]] +<todo>Determine whether the child requirements under MO-001 provide complete coverage of the approved intent of MO-001.</todo>
-  * [[dido:02-crusible:06-machine-images-and-image-layers:start|6. Machine Images and Image Layers]] +
-  * [[dido:02-crusible:07-infrastructure-and-deployment:start|7. Infrastructure and Deployment]] +
-  * [[dido:02-crusible:08-dependencies-and-air-gap-operations:start|8. Dependencies and Air-Gap Operations]] +
-  * [[dido:02-crusible:09-compliance-and-security:start|9. Compliance and Security]] +
-  * [[dido:02-crusible:10-reproducibility-provenance-and-traceability:start|10Reproducibility, Provenance, and Traceability]]+
  
-===== ConOps Relationship =====+---- 
 +===== Notes for Editors =====
  
-The Crucible Concept of Operations describes Phase 1 as a command-line utility invoked through CI/CD pipeline steps.+This page should retain the stable parent requirement identifier ''MO-001''.
  
-The Phase 1 workflow:+This page is a non-leaf requirement page and retains a trailing '':start'' in its namespace.
  
-  - Composes image-layer and infrastructure baselines +The child requirements are leaf requirement pages and omit a trailing '':start'' from their namespaces.
-  - Builds and hardens [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]] +
-  - Captures dependencies and compliance findings +
-  - Deploys infrastructure +
-  - Produces supporting [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]+
  
-This workflow provides the operational realization of environment creation, [[dido:99_annexes:annex-b-terms-and-definitions:r:reproducibility|Reproducibility]], security control application, and compliance evaluation.+The ''indexmenu'' displays the child requirement pages contained within the MO-001 namespace. Explicit child-page links may be included while the decomposition is being developed and removed after the child pages have been created and finalized.
  
-===== Delivery Phase ===== +This page preserves:
- +
-Phase 1 and subsequent phases +
- +
-===== Implementation Status ===== +
- +
-Not Assessed +
- +
-Implementation status requires verification against the current Crucible implementation and the applicable acceptance criteria. +
- +
-===== Requirement Status ===== +
- +
-Draft +
- +
-The source System Requirements Specification identifies Version 1.1 as a draft. +
- +
----- +
-===== Notes for Editors =====+
  
-This requirement page should retain the stable requirement identifier `MO-001`.+  * The Original Requirement 
 +  * The assessment of the Original Requirement 
 +  * The reason for decomposition 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] to the proposed replacement requirements 
 +  * The unresolved cross-cutting issues affecting the decomposition 
 +  * The supersession decision
  
-Changes to the Statement SHALL preserve the approved intent of the source requirement.+The Original Requirement should not be marked as superseded until the requirement owner:
  
-Material changes should receive review and should update the related Traceability, verification criteria, and source records.+  * Approves the proposed decomposition 
 +  * Approves the child requirements 
 +  * Confirms that the child requirements collectively preserve the complete approved intent of MO-001 
 +  * Confirms that no additional child requirements are required
  
-The source wording should remain in the Source Statement section unless the controlling System Requirements Specification changes.+After supersession, this page should remain as the parent Traceability record and should continue to preserve the Original Requirement and its assessment.
  
-Do not rename this page once it has been cited externally unless a redirect or move plan is in place.+Material changes to the decomposition should update the child requirements, Requirement Status, Issues, and Traceability records.
  
 ---- ----
  • dido/02-crusible/99-annexes/annex-c-requirements/01-mission-objectives/mo-001/start.1784141750.txt.gz
  • Last modified: 2026/07/15 11:55
  • by nick_dido