Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004d [2026/07/20 08:40] – created nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004d [2026/07/30 05:25] (current) – [Delivery Phase] nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ====== MO-004d — External | + | ====== MO-004d — Disconnected |
| [[dido: | [[dido: | ||
| Line 5: | Line 5: | ||
| ===== Statement ===== | ===== Statement ===== | ||
| - | [[dido: | + | [[dido: |
| ===== Derived From ===== | ===== Derived From ===== | ||
| Line 17: | Line 17: | ||
| > //The system SHALL support both connected and disconnected operational environments.// | > //The system SHALL support both connected and disconnected operational environments.// | ||
| - | MO-004d preserves the implied requirement | + | MO-004d preserves the portion of the Original Requirement |
| The separate requirements derived from MO-004 address: | The separate requirements derived from MO-004 address: | ||
| - | * [[dido: | + | * [[dido: |
| - | * [[dido: | + | * [[dido: |
| - | * [[dido: | + | * [[dido: |
| - | + | ||
| - | ===== Assessment ===== | + | |
| - | + | ||
| - | The Original Requirement does not identify the resource-availability constraint associated with operation in a Disconnected Environment. | + | |
| - | + | ||
| - | The phrase **support both connected and disconnected operational environments** does not identify: | + | |
| - | + | ||
| - | * The boundary of the Disconnected Environment | + | |
| - | * The external resources unavailable within that boundary | + | |
| - | * The resources required by each selected Operational Lifecycle activity | + | |
| - | * The locally available replacements for external repositories, | + | |
| - | * The behavior required when an external resource is unavailable | + | |
| - | * The treatment of attempted external access | + | |
| - | * The Evidence required to demonstrate independence from external resources | + | |
| - | + | ||
| - | MO-004d: | + | |
| - | + | ||
| - | * Identifies [[dido: | + | |
| - | * Identifies execution of a selected Operational Lifecycle activity as the required behavior | + | |
| - | * Identifies the Disconnected Environment boundary as the resource-availability boundary | + | |
| - | * Prohibits access to external resources outside that boundary during execution | + | |
| - | * Separates resource availability from resource authorization | + | |
| - | * Separates External Resource Independence from the general requirement to execute within a Disconnected Environment | + | |
| ===== Rationale ===== | ===== Rationale ===== | ||
| - | A Disconnected Environment does not provide continuous access to resources outside its defined boundary. | + | A [[dido: |
| - | External | + | Each selected Operational Lifecycle activity therefore requires its inputs, dependencies, |
| - | * External Artifact repositories | + | Required resources can include: |
| - | * External package repositories | + | |
| - | * External image registries | + | |
| - | * Public software repositories | + | |
| - | * Cloud-hosted application programming interfaces | + | |
| - | * External identity services | + | |
| - | * External licensing services | + | |
| - | * External configuration services | + | |
| - | * External time services | + | |
| - | * External vulnerability feeds | + | |
| - | * External documentation services | + | |
| - | * External telemetry services | + | |
| - | * External update services | + | |
| - | * External name-resolution services | + | |
| - | Execution within a Disconnected Environment requires the necessary | + | * [[dido: |
| + | * Artifacts | ||
| + | * Software packages | ||
| + | * Machine Images | ||
| + | * Artifact | ||
| + | * Package repositories | ||
| + | * Image registries | ||
| + | * Configuration data | ||
| + | * Security and compliance content | ||
| + | * Identity and authorization information | ||
| + | * Licensing information | ||
| + | * Name-resolution | ||
| + | * Time services | ||
| + | * Build and deployment tools | ||
| + | * Evidence-generation tools | ||
| - | Required resources can enter the Disconnected Environment | + | Resources imported |
| - | External Resource Independence | + | Ensuring resource availability within the environment boundary |
| - | * Predictable execution | + | * Execution |
| * Operation during network outages | * Operation during network outages | ||
| * Operation within restricted network boundaries | * Operation within restricted network boundaries | ||
| * Operation in [[dido: | * Operation in [[dido: | ||
| + | * Detection of hidden external dependencies | ||
| * Controlled dependency capture | * Controlled dependency capture | ||
| * Complete offline transfer preparation | * Complete offline transfer preparation | ||
| * Reproducible execution | * Reproducible execution | ||
| - | * Prevention | + | * Generation |
| - | * Evidence | + | |
| - | This requirement addresses resource availability. MO-004c separately | + | This requirement addresses resource availability. MO-004c separately |
| - | A resource can be available within the environment but unauthorized. A resource can also be authorized for use but unavailable within the environment. The two conditions require separate evaluation. | + | A resource can be available within the environment but not authorized for use. A resource can also be authorized for use but unavailable within the environment. |
| ===== Applies To ===== | ===== Applies To ===== | ||
| Line 97: | Line 75: | ||
| * [[dido: | * [[dido: | ||
| * Environment boundaries | * Environment boundaries | ||
| + | * Required resources | ||
| * External resources | * External resources | ||
| * Local resources | * Local resources | ||
| Line 108: | Line 87: | ||
| * Local package repositories | * Local package repositories | ||
| * Local image registries | * Local image registries | ||
| - | * Local network | + | * Local services |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| * [[dido: | * [[dido: | ||
| * [[dido: | * [[dido: | ||
| Line 122: | Line 96: | ||
| Verification confirms that: | Verification confirms that: | ||
| - | - The applicable | + | - The [[dido: |
| - | - The selected Operational Lifecycle activity is identified | + | - Each selected |
| - | - The resources required by the selected activity are identified | + | - The resources required by each selected activity are identified |
| - | - Each required resource is available within the Disconnected Environment boundary | + | - Each required resource is available within the Disconnected Environment boundary |
| - | - External network connectivity is unavailable during execution | + | - Each imported resource has completed the required transfer, authorization, |
| - | - Crucible executes the selected activity without | + | - [[dido: |
| - | - Each attempted external resource | + | - Each selected activity |
| - | - The selected activity reaches its defined completion condition | + | - Each attempted |
| - | - The selected activity produces its required outputs | + | - Each selected activity reaches its defined completion condition |
| - | - The execution | + | - Each selected activity produces its required outputs |
| + | - The verification | ||
| - | Verification includes: | + | ===== Referenced By ===== |
| - | * Disconnected Environment boundary inspection | + | The following pages reference this requirement: |
| - | * Operational Lifecycle activity inspection | + | |
| - | * Required-resource inventory inspection | + | |
| - | * Local repository inspection | + | |
| - | * Local registry inspection | + | |
| - | * Local service inspection | + | |
| - | * Transfer Bundle inspection | + | |
| - | * Imported dependency inspection | + | |
| - | * Network-disconnection tests | + | |
| - | * Network-traffic inspection | + | |
| - | * Domain-name resolution inspection | + | |
| - | * External-endpoint access testing | + | |
| - | * Hidden-dependency testing | + | |
| - | * Operational Lifecycle execution tests | + | |
| - | * Completion-condition inspection | + | |
| - | * Output inspection | + | |
| - | * Audit-record inspection | + | |
| - | * Evidence inspection | + | |
| - | * Provenance inspection | + | |
| - | * Traceability inspection | + | |
| - | The verification record identifies: | + | {{backlinks> |
| - | - The Disconnected Environment | + | ===== Delivery Phase ===== |
| - | - The environment boundary | + | |
| - | - The selected Operational Lifecycle activity | + | |
| - | - The applicable activity identifier and revision | + | |
| - | - The resources required by the selected activity | + | |
| - | - The resources available within the environment boundary | + | |
| - | - The imported Artifacts and dependencies | + | |
| - | - The local repositories, | + | |
| - | - The network-disconnection condition | + | |
| - | - Each attempted access to an external resource | + | |
| - | - The result of each attempted external access | + | |
| - | - The applicable starting condition | + | |
| - | - The applicable completion condition | + | |
| - | - The execution result | + | |
| - | - The outputs produced | + | |
| - | - Each identified hidden or unresolved external dependency | + | |
| - | - The observed result | + | |
| - | - The generated [[dido: | + | |
| - | ===== Requirements Realized By ===== | + | Implemented and Verified. |
| - | This requirement is realized by: | + | ===== Implementation Status ===== |
| - | * [[dido: | + | < |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | ===== Related Architecture Sections | + | ===== Requirement Status |
| - | * [[dido: | + | < |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | * [[dido: | + | |
| - | ===== Referenced By ===== | + | ---- |
| + | ===== Issues | ||
| - | The following | + | The following |
| - | {{backlinks>.# | + | <todo>Define the boundary of each Disconnected Environment.</ |
| - | ===== Delivery Phase ===== | + | < |
| - | Phase 1 and subsequent phases | + | < |
| - | ===== Implementation Status ===== | + | < |
| - | Not Assessed | + | < |
| - | Implementation status requires verification that the current [[dido: | + | < |
| - | + | ||
| - | ===== Requirement Status ===== | + | |
| - | + | ||
| - | Draft | + | |
| - | + | ||
| - | This requirement derives from MO-004 in the Crucible System Requirements Specification, | + | |
| ---- | ---- | ||
| Line 231: | Line 150: | ||
| This page is a leaf requirement page and omits a trailing '': | This page is a leaf requirement page and omits a trailing '': | ||
| - | Changes to the Statement | + | The parent MO-004 page is a non-leaf page and retains a trailing '': |
| + | |||
| + | Changes to the Statement | ||
| + | |||
| + | * [[dido: | ||
| + | * The selected [[dido: | ||
| + | * The [[dido: | ||
| + | * Availability of all required resources within the environment boundary | ||
| + | * Execution without access to external resources outside the environment boundary | ||
| - | The applicable | + | The definition of each Disconnected Environment should identify: |
| * The environment boundary | * The environment boundary | ||
| Line 243: | Line 170: | ||
| * The required Controlled Inputs | * The required Controlled Inputs | ||
| * The imported Artifacts and dependencies | * The imported Artifacts and dependencies | ||
| - | * The applicable | + | * The transfer and admission processes |
| - | * The required | + | * The monitoring and audit records |
| - | * The required Evidence | + | |
| - | Material changes should receive review and should update the related | + | Material changes should receive review and should update the verification criteria, |
| To reference this requirement Statement from another wiki page, insert: | To reference this requirement Statement from another wiki page, insert: | ||