Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004c [2026/07/21 09:57] – ↷ Links adapted because of a move operation nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004c [2026/07/30 05:24] (current) – [Delivery Phase] nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== MO-004c — Unauthorized | + | ====== MO-004c — Authorized |
| [[dido: | [[dido: | ||
| Line 5: | Line 5: | ||
| ===== Statement ===== | ===== Statement ===== | ||
| - | [[dido: | + | [[dido: |
| ===== Derived From ===== | ===== Derived From ===== | ||
| Line 17: | Line 17: | ||
| > //The system SHALL support both connected and disconnected operational environments.// | > //The system SHALL support both connected and disconnected operational environments.// | ||
| - | MO-004c preserves the implied | + | MO-004c preserves the constraint that [[dido: |
| The separate requirements derived from MO-004 address: | The separate requirements derived from MO-004 address: | ||
| - | * [[dido: | + | * [[dido: |
| - | * [[dido: | + | * [[dido: |
| - | * [[dido: | + | * [[dido: |
| - | + | ||
| - | ===== Assessment ===== | + | |
| - | + | ||
| - | The Original Requirement does not identify the resource-authorization constraints applicable within connected and disconnected operational environments. | + | |
| - | + | ||
| - | The phrase **support both connected and disconnected operational environments** does not identify: | + | |
| - | + | ||
| - | * The resources Crucible is permitted to access | + | |
| - | * The authority that approves a resource for use | + | |
| - | * The operational environment to which the authorization applies | + | |
| - | * The duration or conditions of the authorization | + | |
| - | * The treatment of a resource whose authorization expires or is revoked | + | |
| - | * The behavior required when Crucible encounters an unauthorized resource | + | |
| - | * The Evidence required to demonstrate compliance with the authorization boundary | + | |
| - | + | ||
| - | MO-004c: | + | |
| - | + | ||
| - | * Identifies [[dido: | + | |
| - | * States the prohibited behavior directly through **SHALL NOT** | + | |
| - | * Identifies an unauthorized resource as the prohibited object of access | + | |
| - | * Ties resource authorization to the applicable operational environment | + | |
| - | * Separates authorization from resource availability | + | |
| - | * Separates unauthorized-resource prohibition from connected operation, disconnected operation, and external-resource independence | + | |
| ===== Rationale ===== | ===== Rationale ===== | ||
| Line 62: | Line 39: | ||
| * A resource whose authorization has expired | * A resource whose authorization has expired | ||
| * A resource whose authorization has been revoked | * A resource whose authorization has been revoked | ||
| - | * A resource | + | * A resource |
| - | * A resource | + | * A resource |
| - | An [[dido: | + | An [[dido: |
| - | Prohibiting access | + | Restricting Crucible |
| * Enforcement of environment boundaries | * Enforcement of environment boundaries | ||
| Line 80: | Line 57: | ||
| * Generation of auditable [[dido: | * Generation of auditable [[dido: | ||
| - | This requirement does not require every Authorized Resource to be available. | + | This requirement does not require every Authorized Resource to be available |
| - | This requirement does not establish | + | This requirement does not identify |
| ===== Applies To ===== | ===== Applies To ===== | ||
| Line 114: | Line 91: | ||
| Verification confirms that: | Verification confirms that: | ||
| - | - The applicable | + | - The operational environment is identified |
| - | - The resources authorized | + | - The Authorized Resources |
| - | - Each resource accessed by Crucible has a valid authorization for the operational environment | + | - Each resource accessed by [[dido: |
| - | - Each resource authorization | + | - Each resource authorization |
| - | - Crucible does not access a resource absent from the authorized resource | + | - Crucible does not access a resource absent from the Authorized Resource |
| - Crucible does not access a resource whose authorization has expired or been revoked | - Crucible does not access a resource whose authorization has expired or been revoked | ||
| - Crucible does not access a resource authorized only for another operational environment | - Crucible does not access a resource authorized only for another operational environment | ||
| - Each attempted access to an unauthorized resource is denied | - Each attempted access to an unauthorized resource is denied | ||
| - | - Each attempted unauthorized access is recorded | + | - Each attempted unauthorized |
| - | - The generated Evidence supports | + | - The verification record preserves [[dido: |
| - | Verification includes: | + | ===== Referenced By ===== |
| - | * Authorized Resource inventory inspection | + | The following pages reference this requirement: |
| - | * Resource authorization inspection | + | |
| - | * Authorization-scope inspection | + | |
| - | * Authorization-validity inspection | + | |
| - | * Repository-access testing | + | |
| - | * Registry-access testing | + | |
| - | * Network-service access testing | + | |
| - | * External-endpoint access testing | + | |
| - | * Imported Artifact admission testing | + | |
| - | * Expired-authorization testing | + | |
| - | * Revoked-authorization testing | + | |
| - | * Cross-environment authorization testing | + | |
| - | * Access-denial testing | + | |
| - | * Audit-record inspection | + | |
| - | * Evidence inspection | + | |
| - | * Provenance inspection | + | |
| - | * Traceability inspection | + | |
| - | The verification record identifies: | + | {{backlinks> |
| - | - The applicable operational environment | + | ===== Delivery Phase ===== |
| - | - The Authorized Resource set | + | |
| - | - Each resource accessed during execution | + | |
| - | - The authorization applicable to each accessed resource | + | |
| - | - The authorization scope | + | |
| - | - The authorization status | + | |
| - | - Each attempted unauthorized resource access | + | |
| - | - The denial result for each attempted unauthorized access | + | |
| - | - The audit record associated with each attempted unauthorized access | + | |
| - | - Each identified failure or exception | + | |
| - | - The observed result | + | |
| - | - The generated [[dido: | + | |
| - | ===== Requirements Realized By ===== | + | Implemented and Verified |
| - | This requirement is realized by: | + | ===== Implementation Status ===== |
| - | * [[dido: | + | < |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | ===== Related Architecture Sections | + | ===== Requirement Status |
| - | * [[dido: | + | < |
| - | * [[dido:02-crusible: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | ===== Referenced By ===== | + | ---- |
| + | ===== Issues | ||
| - | The following | + | The following |
| - | {{backlinks>.# | + | <todo>Identify the authority that authorizes resources for each operational environment.</ |
| - | ===== Delivery Phase ===== | + | < |
| - | Phase 1 and subsequent phases | + | < |
| - | ===== Implementation Status ===== | + | < |
| - | Not Assessed | + | < |
| - | + | ||
| - | Implementation status requires verification that the current [[dido: | + | |
| - | + | ||
| - | ===== Requirement Status ===== | + | |
| - | + | ||
| - | Draft | + | |
| - | + | ||
| - | This requirement derives from MO-004 in the Crucible System Requirements Specification, | + | |
| ---- | ---- | ||
| Line 212: | Line 142: | ||
| This page is a leaf requirement page and omits a trailing '': | This page is a leaf requirement page and omits a trailing '': | ||
| - | Changes to the Statement | + | The parent MO-004 page is a non-leaf page and retains a trailing '': |
| + | |||
| + | Changes to the Statement | ||
| + | |||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * The identified operational environment as the authorization context | ||
| + | * Prohibition of access to resources outside the Authorized Resource set | ||
| The authorization record for each Authorized Resource should identify: | The authorization record for each Authorized Resource should identify: | ||
| Line 218: | Line 155: | ||
| * The resource identifier | * The resource identifier | ||
| * The resource type | * The resource type | ||
| - | * The applicable | + | * The operational environment |
| * The permitted use | * The permitted use | ||
| * The authorizing authority | * The authorizing authority | ||
| Line 224: | Line 161: | ||
| * The authorization status | * The authorization status | ||
| * The authorization expiration condition | * The authorization expiration condition | ||
| - | * Any applicable | + | * Any restrictions |
| - | * The supporting Evidence | + | |
| - | Material changes should receive review and should update the related | + | Material changes should receive review and should update the verification criteria, |
| To reference this requirement Statement from another wiki page, insert: | To reference this requirement Statement from another wiki page, insert: | ||