dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004:start

This is an old revision of the document!


MO-004

Crucible SHALL execute the applicable Operational Lifecycle activities in both Connected Environments and Disconnected Environments using only the resources authorized and available within each environment.

The system SHALL support both connected and disconnected operational environments.

Crucible System Requirements Specification, Version 1.1 Draft, Mission Objectives, MO-004.

The source statement expresses the approved mission objective but does not provide a fully testable formulation.

The following Specification Discipline and Authoring findings apply:

  • The system does not use the defined system name
  • Support is a weak verb that does not identify the behavior Crucible performs
  • Operational environments does not identify the environmental characteristics, available resources, access restrictions, or applicable activities
  • The source statement does not identify which Operational Lifecycle activities must operate in each environment
  • The source statement does not identify whether a Disconnected Environment may obtain required resources through an approved transfer process
  • The source statement does not define how verification distinguishes a connected workflow from a disconnected workflow

The normalized Statement replaces the weak verb with execute, identifies the applicable environments, and constrains execution to the resources authorized and available within each environment.

Organizations may construct, deploy, maintain, and validate infrastructure in environments with different network access conditions.

A Connected Environment may access approved external repositories, services, and providers during execution.

A Disconnected Environment cannot depend on unavailable external network services during execution. An Air-Gapped Environment imposes additional physical or logical separation requirements.

Crucible addresses these conditions by coordinating:

The connected workflow captures the dependencies, artifacts, and Compliance Findings required by the disconnected workflow.

An approved transfer process moves the resulting transfer bundle into the target Disconnected Environment.

  1. Verification SHALL confirm that Crucible executes the applicable Operational Lifecycle activities in a Connected Environment
  2. Verification SHALL confirm that Crucible executes the applicable Operational Lifecycle activities in a Disconnected Environment
  3. Verification SHALL confirm that the disconnected workflow does not require access to external network resources that are unavailable within the target environment
  4. Verification SHALL confirm that the connected workflow captures the dependencies required by the disconnected workflow
  5. Verification SHALL confirm that the connected workflow produces a transferable bundle containing the required dependencies, artifacts, provenance information, and Compliance Findings
  6. Verification SHALL confirm that the approved transfer process preserves the integrity of the transfer bundle
  7. Verification SHALL confirm that the target Disconnected Environment imports and validates the transfer bundle
  8. Verification SHALL confirm that the disconnected workflow uses only resources authorized and available within the target environment
  9. Verification SHALL confirm that equivalent controlled inputs produce results that satisfy the applicable acceptance criteria in both environments
  10. Verification SHALL confirm that the workflow records the differences between connected and disconnected execution conditions
  11. Verification SHALL confirm that deployment and Evidence records preserve Traceability across the transfer boundary

Verification may include:

  • Connected build tests
  • Disconnected build tests
  • Dependency capture tests
  • Dependency store inspection
  • Transfer bundle export tests
  • Transfer bundle integrity tests
  • Transfer bundle import tests
  • Offline package repository tests
  • Offline provider repository tests
  • Machine Image build tests
  • Compliance assessment tests
  • Evidence generation tests
  • Network isolation tests
  • Air-Gapped Environment demonstrations
  • End-to-end CI/CD Pipeline tests

The verification record SHALL identify:

  1. The tested Baselines
  2. The applicable Operational Lifecycle activities
  3. The connected execution conditions
  4. The disconnected execution conditions
  5. The authorized external resources
  6. The prohibited external resources
  7. The captured dependencies
  8. The dependency store
  9. The transfer bundle
  10. The bundle integrity verification result
  11. The transfer authorization
  12. The imported resources
  13. The controlled inputs
  14. The applicable acceptance criteria
  15. The observed results
  16. The generated Evidence

The wiki Backlinks function provides the current list of pages that reference `MO-004`.

Incoming traceability should be derived dynamically from backlinks rather than maintained as a duplicate manual list.

Backlinks identify incoming references but do not define the semantics of each relationship. Referencing pages should identify whether the relationship represents realization, refinement, verification, dependency, or another defined traceability relationship.

The Crucible Concept of Operations describes a connected to disconnected supply chain.

In a Connected Environment, Crucible:

  • Resolves required dependencies
  • Builds and hardens Machine Images
  • Captures operating system packages and installation media
  • Produces a transfer bundle

In a Disconnected Environment, Crucible:

  • Imports the transfer bundle
  • Validates the transferred content
  • Populates internal dependency repositories
  • Performs offline builds and updates
  • Preserves artifact provenance and Traceability

The ConOps identifies dependency capture, compressed bundle transfer, and enclave repository population as the operational realization of disconnected execution.

Phase 1 and subsequent phases

Not Assessed

Implementation status requires verification of the applicable Operational Lifecycle activities in both a Connected Environment and a Disconnected Environment.

Draft

The source System Requirements Specification identifies Version 1.1 as a draft.


This requirement page should retain the stable requirement identifier `MO-004`.

Changes to the Statement SHALL preserve the approved intent of the source requirement.

Material changes should receive review and should update the related outbound traceability, verification criteria, acceptance criteria, and source records.

The Source Statement should preserve the original wording from the controlling System Requirements Specification.

Incoming traceability should use the wiki Backlinks function rather than a manually maintained list.

The shared Terms and Definitions corpus should include definitions for:

  • Authorized Resource
  • Dependency Capture
  • Dependency Store
  • Disconnected Execution
  • Enclave
  • Network Isolation
  • Offline Repository
  • Offline Transfer
  • Operational Environment
  • Transfer Authorization
  • Transfer Boundary
  • Transfer Bundle
  • Transfer Bundle Integrity

The proposed namespaces are:

  • `dido:99_annexes:annex-b-terms-and-definitions:a:authorized_resource`
  • `dido:99_annexes:annex-b-terms-and-definitions:d:dependency_capture`
  • `dido:99_annexes:annex-b-terms-and-definitions:d:dependency_store`
  • `dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_execution`
  • `dido:99_annexes:annex-b-terms-and-definitions:e:enclave`
  • `dido:99_annexes:annex-b-terms-and-definitions:n:network_isolation`
  • `dido:99_annexes:annex-b-terms-and-definitions:o:offline_repository`
  • `dido:99_annexes:annex-b-terms-and-definitions:o:offline_transfer`
  • `dido:99_annexes:annex-b-terms-and-definitions:o:operational_environment`
  • `dido:99_annexes:annex-b-terms-and-definitions:t:transfer_authorization`
  • `dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary`
  • `dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle`
  • `dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle_integrity`

Do not rename this page once it has been cited externally unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/01-mission-objectives/mo-004/start.1784144911.txt.gz
  • Last modified: 2026/07/15 12:48
  • by nick_dido