dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004d

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004d [2026/07/20 08:40] – created nick_didodido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004d [2026/07/30 05:25] (current) – [Delivery Phase] nick_dido
Line 1: Line 1:
-====== MO-004d — External Resource Independence ======+====== MO-004d — Disconnected Resource Availability ======
  
 [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:start|Go to MO-004 — Connected and Disconnected Operations]] [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:start|Go to MO-004 — Connected and Disconnected Operations]]
Line 5: Line 5:
 ===== Statement ===== ===== Statement =====
  
-[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL execute each selected [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] activity in a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] without accessing an external resource outside the environment boundary.+[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL execute each selected [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] activity in a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] using only the required resources available within the environment boundary.
  
 ===== Derived From ===== ===== Derived From =====
Line 17: Line 17:
 > //The system SHALL support both connected and disconnected operational environments.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] > //The system SHALL support both connected and disconnected operational environments.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
  
-MO-004d preserves the implied requirement that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] operates within a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] without relying on external resources outside the environment boundary.+MO-004d preserves the portion of the Original Requirement that requires the resources needed for disconnected operation to be available within the Disconnected Environment boundary.
  
 The separate requirements derived from MO-004 address: The separate requirements derived from MO-004 address:
  
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004a|MO-004a — Connected Environment Operation]] +  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004a|MO-004a — Connected Environment Operations]] 
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004b|MO-004b — Disconnected Environment Operation]] +  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004b|MO-004b — Disconnected Environment Operations]] 
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004c|MO-004c — Unauthorized Resource Prohibition]] +  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:mo-004c|MO-004c — Authorized Resource Use]]
- +
-===== Assessment ===== +
- +
-The Original Requirement does not identify the resource-availability constraint associated with operation in a Disconnected Environment. +
- +
-The phrase **support both connected and disconnected operational environments** does not identify: +
- +
-  * The boundary of the Disconnected Environment +
-  * The external resources unavailable within that boundary +
-  * The resources required by each selected Operational Lifecycle activity +
-  * The locally available replacements for external repositories, registries, services, and dependencies +
-  * The behavior required when an external resource is unavailable +
-  * The treatment of attempted external access +
-  * The Evidence required to demonstrate independence from external resources +
- +
-MO-004d: +
- +
-  * Identifies [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor +
-  * Identifies execution of a selected Operational Lifecycle activity as the required behavior +
-  * Identifies the Disconnected Environment boundary as the resource-availability boundary +
-  * Prohibits access to external resources outside that boundary during execution +
-  * Separates resource availability from resource authorization +
-  * Separates External Resource Independence from the general requirement to execute within a Disconnected Environment+
  
 ===== Rationale ===== ===== Rationale =====
  
-A Disconnected Environment does not provide continuous access to resources outside its defined boundary.+[[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] does not provide continuous access to resources outside its defined boundary.
  
-External resources can include:+Each selected Operational Lifecycle activity therefore requires its inputs, dependencies, tools, repositories, registries, services, and other resources to be available within the environment boundary before execution.
  
-  * External Artifact repositories +Required resources can include:
-  * External package repositories +
-  * External image registries +
-  * Public software repositories +
-  * Cloud-hosted application programming interfaces +
-  * External identity services +
-  * External licensing services +
-  * External configuration services +
-  * External time services +
-  * External vulnerability feeds +
-  * External documentation services +
-  * External telemetry services +
-  * External update services +
-  * External name-resolution services+
  
-Execution within a Disconnected Environment requires the necessary [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]], dependencies, tools, repositoriesregistriesservicesand other resources to exist within the environment boundary before execution begins.+  * [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]] 
 +  * Artifacts 
 +  * Software packages 
 +  * Machine Images 
 +  * Artifact repositories 
 +  * Package repositories 
 +  * Image registries 
 +  * Configuration data 
 +  * Security and compliance content 
 +  * Identity and authorization information 
 +  * Licensing information 
 +  * Name-resolution services 
 +  * Time services 
 +  * Build and deployment tools 
 +  * Evidence-generation tools
  
-Required resources can enter the Disconnected Environment through an approved transfer and admission process. After successful transfer, authorization, integrity verification, and admission, the resources become available within the environment boundary and no longer constitute external resources for the applicable execution.+Resources imported through an approved transfer process become available within the Disconnected Environment only after the required transfer, authorization, integrity, provenance, and admission checks succeed.
  
-External Resource Independence supports:+Ensuring resource availability within the environment boundary supports:
  
-  * Predictable execution without external connectivity+  * Execution without continuous external connectivity
   * Operation during network outages   * Operation during network outages
   * Operation within restricted network boundaries   * Operation within restricted network boundaries
   * Operation in [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]   * Operation in [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]
 +  * Detection of hidden external dependencies
   * Controlled dependency capture   * Controlled dependency capture
   * Complete offline transfer preparation   * Complete offline transfer preparation
   * Reproducible execution   * Reproducible execution
-  * Prevention of hidden external dependencies +  * Generation of Evidence for disconnected operation
-  * Evidence of disconnected operation+
  
-This requirement addresses resource availability. MO-004c separately prohibits access to resources that lack authorization for the applicable operational environment.+This requirement addresses resource availability. MO-004c separately requires Crucible to use only Authorized Resources.
  
-A resource can be available within the environment but unauthorized. A resource can also be authorized for use but unavailable within the environment. The two conditions require separate evaluation.+A resource can be available within the environment but not authorized for use. A resource can also be authorized for use but unavailable within the environment.
  
 ===== Applies To ===== ===== Applies To =====
Line 97: Line 75:
   * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]   * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]
   * Environment boundaries   * Environment boundaries
 +  * Required resources
   * External resources   * External resources
   * Local resources   * Local resources
Line 108: Line 87:
   * Local package repositories   * Local package repositories
   * Local image registries   * Local image registries
-  * Local network services +  * Local services
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipelines]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_deployment|Infrastructure Deployments]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:p:provisioning|Provisioning]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:compliance_assessment|Compliance Assessments]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_validation|Deployment Validation]]+
   * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]   * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]   * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]
Line 122: Line 96:
 Verification confirms that: Verification confirms that:
  
-  - The applicable Disconnected Environment boundary is identified +  - The [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] boundary is identified 
-  - The selected Operational Lifecycle activity is identified +  - Each selected [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] activity is identified 
-  - The resources required by the selected activity are identified +  - The resources required by each selected activity are identified 
-  - Each required resource is available within the Disconnected Environment boundary +  - Each required resource is available within the Disconnected Environment boundary before execution 
-  - External network connectivity is unavailable during execution +  - Each imported resource has completed the required transfer, authorization, integrity, provenance, and admission checks 
-  - Crucible executes the selected activity without accessing an external resource outside the environment boundary +  - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] executes each selected activity using only resources available within the environment boundary 
-  - Each attempted external resource access is detected and recorded +  - Each selected activity executes without access to an external resource outside the environment boundary 
-  - The selected activity reaches its defined completion condition +  - Each attempted access to an external resource is detected and recorded 
-  - The selected activity produces its required outputs +  - Each selected activity reaches its defined completion condition 
-  - The execution record preserves the required EvidenceProvenance, and Traceability+  - Each selected activity produces its required outputs 
 +  - The verification record preserves [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] among the Disconnected Environment, selected activity, required resourcesavailable resources, execution result, and outputs produced
  
-Verification includes:+===== Referenced By =====
  
-  * Disconnected Environment boundary inspection +The following pages reference this requirement:
-  * Operational Lifecycle activity inspection +
-  * Required-resource inventory inspection +
-  * Local repository inspection +
-  * Local registry inspection +
-  * Local service inspection +
-  * Transfer Bundle inspection +
-  * Imported dependency inspection +
-  * Network-disconnection tests +
-  * Network-traffic inspection +
-  * Domain-name resolution inspection +
-  * External-endpoint access testing +
-  * Hidden-dependency testing +
-  * Operational Lifecycle execution tests +
-  * Completion-condition inspection +
-  * Output inspection +
-  * Audit-record inspection +
-  * Evidence inspection +
-  * Provenance inspection +
-  * Traceability inspection+
  
-The verification record identifies:+{{backlinks>.#dido:02-crusible}}
  
-  - The Disconnected Environment +===== Delivery Phase =====
-  - The environment boundary +
-  - The selected Operational Lifecycle activity +
-  - The applicable activity identifier and revision +
-  - The resources required by the selected activity +
-  - The resources available within the environment boundary +
-  - The imported Artifacts and dependencies +
-  - The local repositories, registries, and services used during execution +
-  - The network-disconnection condition +
-  - Each attempted access to an external resource +
-  - The result of each attempted external access +
-  - The applicable starting condition +
-  - The applicable completion condition +
-  - The execution result +
-  - The outputs produced +
-  - Each identified hidden or unresolved external dependency +
-  - The observed result +
-  - The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]+
  
-===== Requirements Realized By =====+Implemented and Verified.
  
-This requirement is realized by:+===== Implementation Status =====
  
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-002|OR-002 — Deployment Environments]] +<todo>Assess whether the current Crucible implementation executes each selected Operational Lifecycle activity using only the required resources available within the Disconnected Environment boundary.</todo>
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003|OR-003 — Classified and Unclassified Environments]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-005|OR-005 — Distributed Environment Management]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-01-configuration-management:start|FR-CFG-001 through FR-CFG-005]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-02-image-management:start|FR-IMG-001 through FR-IMG-006]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-03-deployment-orchestration:start|FR-DEP-001 through FR-DEP-007]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:start|FR-AG-001 through FR-AG-005]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-08-devsecops-integration:start|FR-DSO-001 through FR-DSO-006]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-09-baseline-composition-and-workspace:start|FR-BAS-001 through FR-BAS-004]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-10-dependency-capture-and-offline-transfer:start|FR-DEPC-001 through FR-DEPC-005]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:11-interoperability-requirements:start|INT-001 through INT-007]]+
  
-===== Related Architecture Sections =====+===== Requirement Status =====
  
-  * [[dido:02-crusible:05-descriptions-composition-and-baselines:start|5. DescriptionsComposition, and Baselines]] +<todo>Review and accept MO-004d as a proposed derived requirement created from the evaluation and decomposition of MO-004 in the Crucible System Requirements SpecificationVersion 1.1 Draft.</todo>
-  * [[dido:02-crusible:06-machine-images-and-image-layers:start|6Machine Images and Image Layers]] +
-  * [[dido:02-crusible:07-infrastructure-and-deployment:start|7Infrastructure and Deployment]] +
-  * [[dido:02-crusible:08-dependencies-and-air-gap-operations:start|8. Dependencies and Air Gap Operations]] +
-  * [[dido:02-crusible:09-compliance-and-security:start|9. Compliance and Security]] +
-  * [[dido:02-crusible:10-reproducibility-provenance-and-traceability:start|10. Reproducibility, Provenance, and Traceability]]+
  
-===== Referenced By =====+---- 
 +===== Issues =====
  
-The following pages reference this requirement:+The following unresolved issues affect this requirement:
  
-{{backlinks>.#dido:02-crusible}}+<todo>Define the boundary of each Disconnected Environment.</todo>
  
-===== Delivery Phase =====+<todo>Identify the controlling source that determines the resources required by each selected Operational Lifecycle activity.</todo>
  
-Phase 1 and subsequent phases+<todo>Define when a resource is considered available within a Disconnected Environment.</todo>
  
-===== Implementation Status =====+<todo>Define the transfer, authorization, integrity, provenance, and admission checks required before an imported resource becomes available.</todo>
  
-Not Assessed+<todo>Define the behavior required when a resource needed by a selected Operational Lifecycle activity is unavailable within the environment boundary.</todo>
  
-Implementation status requires verification that the current [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] implementation executes selected Operational Lifecycle activities in a Disconnected Environment without accessing external resources outside the environment boundary. +<todo>Define how attempted access to external resources is detected and recorded.</todo>
- +
-===== Requirement Status ===== +
- +
-Draft +
- +
-This requirement derives from MO-004 in the Crucible System Requirements Specification, Version 1.1 Draft.+
  
 ---- ----
Line 231: Line 150:
 This page is a leaf requirement page and omits a trailing '':start'' from its namespace. This page is a leaf requirement page and omits a trailing '':start'' from its namespace.
  
-Changes to the Statement SHALL preserve the External Resource Independence intent derived from MO-004.+The parent MO-004 page is a non-leaf page and retains a trailing '':start'' in its namespace. 
 + 
 +Changes to the Statement should preserve
 + 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor 
 +  * The selected [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] activity as the required behavior 
 +  * The [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] boundary as the resource-availability boundary 
 +  * Availability of all required resources within the environment boundary 
 +  * Execution without access to external resources outside the environment boundary
  
-The applicable Disconnected Environment definition should identify:+The definition of each Disconnected Environment should identify:
  
   * The environment boundary   * The environment boundary
Line 243: Line 170:
   * The required Controlled Inputs   * The required Controlled Inputs
   * The imported Artifacts and dependencies   * The imported Artifacts and dependencies
-  * The applicable transfer and admission processes +  * The transfer and admission processes 
-  * The required monitoring and audit records +  * The monitoring and audit records
-  * The required Evidence+
  
-Material changes should receive review and should update the related verification criteria, requirements realization, related architecture sections, and source records.+Material changes should receive review and should update the verification criteria, source records, and Issues section.
  
 To reference this requirement Statement from another wiki page, insert: To reference this requirement Statement from another wiki page, insert:
  • dido/02-crusible/99-annexes/annex-c-requirements/01-mission-objectives/mo-004/mo-004d.1784562043.txt.gz
  • Last modified: 2026/07/20 08:40
  • by nick_dido