This is an old revision of the document!
MO-004
Statement
Crucible SHALL execute the applicable Operational Lifecycle activities in both Connected Environments and Disconnected Environments using only the resources authorized and available within each environment.
Source Statement
The system SHALL support both connected and disconnected operational environments.
Source
Crucible System Requirements Specification, Version 1.1 Draft, Mission Objectives, MO-004.
Assessment
The source statement expresses the approved mission objective but does not provide a fully testable formulation.
The following Specification Discipline and Authoring findings apply:
-
The system does not use the defined system name
-
Support is a weak verb that does not identify the behavior Crucible performs
-
Operational environments does not identify the environmental characteristics, available resources, access restrictions, or applicable activities
-
The source statement does not identify which Operational Lifecycle activities must operate in each environment
-
The source statement does not identify whether a Disconnected Environment may obtain required resources through an approved transfer process
-
The source statement does not define how verification distinguishes a connected workflow from a disconnected workflow
The normalized Statement replaces the weak verb with execute, identifies the applicable environments, and constrains execution to the resources authorized and available within each environment.
Rationale
Organizations may construct, deploy, maintain, and validate infrastructure in environments with different network access conditions.
A Connected Environment may access approved external repositories, services, and providers during execution.
A Disconnected Environment cannot depend on unavailable external network services during execution. An Air-Gapped Environment imposes additional physical or logical separation requirements.
Crucible addresses these conditions by coordinating:
-
Reusable Baselines
-
Machine Image construction
-
Dependency capture
-
Offline transfer
-
Compliance assessment
-
Evidence generation
The connected workflow captures the dependencies, artifacts, and Compliance Findings required by the disconnected workflow.
An approved transfer process moves the resulting transfer bundle into the target Disconnected Environment.
Applies To
This requirement applies to:
-
Machine Image construction
-
Dependency capture
-
Dependency stores
-
Transfer bundles
-
Offline transfer
-
Compliance assessment
Verification
-
Verification SHALL confirm that Crucible executes the applicable Operational Lifecycle activities in a Connected Environment
-
Verification SHALL confirm that Crucible executes the applicable Operational Lifecycle activities in a Disconnected Environment
-
Verification SHALL confirm that the disconnected workflow does not require access to external network resources that are unavailable within the target environment
-
Verification SHALL confirm that the connected workflow captures the dependencies required by the disconnected workflow
-
Verification SHALL confirm that the connected workflow produces a transferable bundle containing the required dependencies, artifacts, provenance information, and Compliance Findings
-
Verification SHALL confirm that the approved transfer process preserves the integrity of the transfer bundle
-
Verification SHALL confirm that the target Disconnected Environment imports and validates the transfer bundle
-
Verification SHALL confirm that the disconnected workflow uses only resources authorized and available within the target environment
-
Verification SHALL confirm that equivalent controlled inputs produce results that satisfy the applicable acceptance criteria in both environments
-
Verification SHALL confirm that the workflow records the differences between connected and disconnected execution conditions
-
Verification SHALL confirm that deployment and Evidence records preserve Traceability across the transfer boundary
Verification may include:
-
Connected build tests
-
Disconnected build tests
-
Dependency capture tests
-
Dependency store inspection
-
Transfer bundle export tests
-
Transfer bundle integrity tests
-
Transfer bundle import tests
-
Offline package repository tests
-
Offline provider repository tests
-
Machine Image build tests
-
Compliance assessment tests
-
Evidence generation tests
-
Network isolation tests
-
Air-Gapped Environment demonstrations
-
End-to-end CI/CD Pipeline tests
The verification record SHALL identify:
-
The tested Crucible Description
-
The tested Baselines
-
The applicable Operational Lifecycle activities
-
The connected execution conditions
-
The disconnected execution conditions
-
The authorized external resources
-
The prohibited external resources
-
The captured dependencies
-
The dependency store
-
The transfer bundle
-
The bundle integrity verification result
-
The transfer authorization
-
The imported resources
-
The controlled inputs
-
The applicable acceptance criteria
-
The observed results
-
The generated Evidence
Outgoing Traceability
This requirement is realized by:
This requirement also relates to:
Referenced By
The wiki Backlinks function provides the current list of pages that reference `MO-004`.
Incoming traceability should be derived dynamically from backlinks rather than maintained as a duplicate manual list.
Backlinks identify incoming references but do not define the semantics of each relationship. Referencing pages should identify whether the relationship represents realization, refinement, verification, dependency, or another defined traceability relationship.
ConOps Relationship
The Crucible Concept of Operations describes a connected to disconnected supply chain.
In a Connected Environment, Crucible:
-
Resolves required dependencies
-
Builds and hardens Machine Images
-
Captures operating system packages and installation media
-
Captures Compliance Findings
-
Produces a transfer bundle
In a Disconnected Environment, Crucible:
-
Imports the transfer bundle
-
Validates the transferred content
-
Populates internal dependency repositories
-
Performs offline builds and updates
-
Performs Infrastructure Deployment
-
Preserves artifact provenance and Traceability
The ConOps identifies dependency capture, compressed bundle transfer, and enclave repository population as the operational realization of disconnected execution.
Delivery Phase
Phase 1 and subsequent phases
Implementation Status
Not Assessed
Implementation status requires verification of the applicable Operational Lifecycle activities in both a Connected Environment and a Disconnected Environment.
Requirement Status
Draft
The source System Requirements Specification identifies Version 1.1 as a draft.
Notes for Editors
This requirement page should retain the stable requirement identifier `MO-004`.
Changes to the Statement SHALL preserve the approved intent of the source requirement.
Material changes should receive review and should update the related outbound traceability, verification criteria, acceptance criteria, and source records.
The Source Statement should preserve the original wording from the controlling System Requirements Specification.
Incoming traceability should use the wiki Backlinks function rather than a manually maintained list.
The shared Terms and Definitions corpus should include definitions for:
-
Authorized Resource
-
Dependency Capture
-
Dependency Store
-
Disconnected Execution
-
Enclave
-
Network Isolation
-
Offline Repository
-
Offline Transfer
-
Operational Environment
-
Transfer Authorization
-
Transfer Boundary
-
Transfer Bundle
-
Transfer Bundle Integrity
The proposed namespaces are:
-
`dido:99_annexes:annex-b-terms-and-definitions:a:authorized_resource`
-
`dido:99_annexes:annex-b-terms-and-definitions:d:dependency_capture`
-
`dido:99_annexes:annex-b-terms-and-definitions:d:dependency_store`
-
`dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_execution`
-
`dido:99_annexes:annex-b-terms-and-definitions:e:enclave`
-
`dido:99_annexes:annex-b-terms-and-definitions:n:network_isolation`
-
`dido:99_annexes:annex-b-terms-and-definitions:o:offline_repository`
-
`dido:99_annexes:annex-b-terms-and-definitions:o:offline_transfer`
-
`dido:99_annexes:annex-b-terms-and-definitions:o:operational_environment`
-
`dido:99_annexes:annex-b-terms-and-definitions:t:transfer_authorization`
-
`dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary`
-
`dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle`
-
`dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle_integrity`
Do not rename this page once it has been cited externally unless a redirect or move plan is in place.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.