dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001a

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001a [2026/07/21 09:55] nick_didodido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001a [2026/07/30 05:30] (current) – [Delivery Phase] nick_dido
Line 5: Line 5:
 ===== Statement ===== ===== Statement =====
  
-[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL execute each Crucible operation assigned to a Developer by the applicable operational scenario in response to the Developer interaction specified for that operation.+[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform each Crucible operation allocated to the Developer Role.
  
 ===== Derived From ===== ===== Derived From =====
Line 23: Line 23:
 >> //Compliance Officers//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] >> //Compliance Officers//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
  
-OR-001a preserves the intent that Developers participate in Crucible operation by requiring Crucible to execute each operation assigned to a Developer by the applicable operational scenario.+OR-001a preserves the intent that Developers participate in Crucible operation by requiring Crucible to perform each operation allocated to the Developer Role.
  
 The separate requirements derived from OR-001 address: The separate requirements derived from OR-001 address:
Line 32: Line 32:
   * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001e|OR-001e — Security Engineer Operations]]   * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001e|OR-001e — Security Engineer Operations]]
   * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001f|OR-001f — Compliance Officer Operations]]   * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001f|OR-001f — Compliance Officer Operations]]
- 
-===== Assessment ===== 
- 
-The Original Requirement identifies Developers as a category of users that participates in Crucible operation but does not identify: 
- 
-  * The Crucible operations assigned to a Developer 
-  * The operational scenarios in which a Developer participates 
-  * The Developer interaction that causes Crucible to execute an assigned operation 
-  * The inputs supplied by a Developer 
-  * The outputs presented to a Developer 
-  * The completion condition for an operation assigned to a Developer 
-  * The Evidence required to demonstrate successful operation 
-  * The distinction between Developer participation and participation by another identified user category 
- 
-The phrase **support operation by Developers** does not identify an observable Crucible behavior. 
- 
-OR-001a: 
- 
-  * Identifies [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor 
-  * Identifies the Developer as the applicable user category 
-  * Requires the applicable operational scenario to assign the operation to a Developer 
-  * Requires the applicable operational scenario to specify the Developer interaction 
-  * Requires Crucible to execute the assigned operation in response to the specified Developer interaction 
-  * Separates Developer operation from operation by the other identified user categories 
- 
-OR-001a does not establish: 
- 
-  * That every Crucible operation applies to a Developer 
-  * That every Developer performs the same operations 
-  * That every operational scenario assigns the same operations to a Developer 
-  * A role-assignment mechanism 
-  * A role-based authorization model 
-  * A particular access-control model 
-  * A particular user interface 
-  * A particular interaction mechanism 
-  * Permissions not established by another controlling requirement 
  
 ===== Rationale ===== ===== Rationale =====
  
-Separating Developer operation from operation by the other identified user categories provides an independently testable and traceable requirement. +Developers require access to the Crucible operations allocated to the Developer Role.
- +
-The applicable operational scenario establishes the context needed to determine: +
- +
-  * Which Crucible operation applies to a Developer +
-  * Which Developer interaction applies to the operation +
-  * Which inputs the Developer supplies +
-  * Which outputs the Developer receives or reviews +
-  * Which completion condition applies +
-  * Which failures and exceptions apply +
-  * Which Evidence demonstrates execution of the operation +
- +
-The [[dido:02-crusible:99-annexes:annex-b:cr-002|Crucible Concept of Operations [C2]]] identifies Build, Capture, and Deploy as high-level Crucible operations. +
- +
-The Concept of Operations also addresses: +
- +
-  * Phase 1 command-line operation +
-  * CI/CD pipeline integration +
-  * Image-layer baseline composition +
-  * Infrastructure baseline composition +
-  * Machine Image construction +
-  * Dependency capture +
-  * Compliance-finding capture +
-  * Infrastructure deployment +
-  * Connected-to-disconnected transfer +
-  * Offline package-repository population +
-  * Compliance Evidence generation +
-  * Phase 2 web management +
-  * Strategic native execution+
  
-The applicable operational scenario determines which of these operations and interactions apply to Developer.+This requirement ensures that Crucible performs each operation allocated to the Developer Role.
  
-This requirement does not allocate every identified Crucible operation to a Developer.+Separating Developer operations from operations allocated to other user categories supports independent verification, [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]], and determination of whether Crucible satisfies the operational needs assigned to Developers.
  
-This requirement does not define the detailed behavior of BuildCapture, Deploy, or another Crucible operation. Separate functional and operational requirements define those behaviors.+Without this requirement, Crucible could perform operations allocated to other user categories while failing to perform the operations allocated to the Developer Role.
  
 ===== Applies To ===== ===== Applies To =====
Line 113: Line 49:
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]
   * Developers   * Developers
-  * Applicable operational scenarios +  * Developer Role 
-  * Crucible operations assigned to Developers +  * Crucible operations allocated to the Developer Role 
-  * Developer interactions specified by applicable operational scenarios +  * [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]]
-  * Developer inputs+
   * Operation status   * Operation status
   * Operation results   * Operation results
   * Operation failures   * Operation failures
   * Operation exceptions   * Operation exceptions
-  * Build operations assigned to Developers 
-  * Capture operations assigned to Developers 
-  * Deploy operations assigned to Developers 
-  * Phase 1 command-line operation 
-  * CI/CD pipeline integration 
-  * Phase 2 web management 
-  * Strategic native execution 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environments]] 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]] 
   * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]]   * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]   * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]   * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]   * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environments]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]
  
 ===== Verification ===== ===== Verification =====
Line 140: Line 68:
 Verification confirms that: Verification confirms that:
  
-  The applicable operational scenario identifies the Developer +  The Developer Role is identified 
-  # The applicable operational scenario identifies each Crucible operation assigned to the Developer +  - Each Crucible operation allocated to the Developer Role is identified 
-  # The applicable operational scenario identifies the Developer interaction associated with each assigned operation +  - Crucible performs each operation allocated to the Developer Role 
-  # Crucible receives the specified Developer interaction +  The performed operation corresponds to the allocated operation 
-  # Crucible executes the operation assigned to the Developer +  Crucible produces each status, result, failure indication, exception indication, [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]][[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] item, or other output specified for the operation 
-  The executed operation corresponds to the operation identified by the applicable operational scenario +  - The verification record preserves [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] between the Developer Role, the allocated operationand the performed operation
-  Crucible produces the status, result, failure, exception, Artifact, Evidence, or other output specified for the operation +
-  # The verification record preserves Traceability between the applicable operational scenario, Developer interaction, and executed operation +
- +
-Verification includes: +
- +
-  * Applicable operational scenario inspection +
-  * Developer identification inspection +
-  * Assigned-operation inspection +
-  * Developer-interaction inspection +
-  * Developer-input inspection +
-  * Execution of each operation assigned to the Developer +
-  * Operation-status inspection +
-  * Operation-result inspection +
-  * Failure-condition testing +
-  * Exception-condition testing +
-  * Artifact inspection +
-  * Evidence inspection +
-  * Provenance inspection +
-  * Traceability inspection +
- +
-The verification record identifies: +
- +
-  # The applicable operational scenario +
-  # The Developer +
-  # The assigned Crucible operation +
-  # The specified Developer interaction +
-  # Each Developer input +
-  # The executed Crucible operation +
-  # The operation start condition +
-  # The operation completion condition +
-  # Each generated status or result +
-  # Each observed failure or exception +
-  # Each generated [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]] +
-  # The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] +
-  # The associated [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] +
-  # The associated [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] +
- +
-===== Requirements Realized By ===== +
- +
-This requirement is realized by: +
- +
-  * Requirements that define Build operations assigned to Developers +
-  * Requirements that define Capture operations assigned to Developers +
-  * Requirements that define Deploy operations assigned to Developers +
-  * Requirements that define Phase 1 command-line interactions +
-  * Requirements that define CI/CD pipeline interactions +
-  * Requirements that define Developer inputs +
-  * Requirements that define operation status and results +
-  * Requirements that define operation failures and exceptions +
-  * Requirements that define generated Artifacts and Evidence +
- +
-===== Related Architecture Sections ===== +
- +
-  * [[dido:02-crusible:04-operational-concepts:start|4. Operational Concepts]] +
-  * [[dido:02-crusible:05-descriptions-composition-and-baselines:start|5. Descriptions, Composition, and Baselines]] +
-  * [[dido:02-crusible:07-infrastructure-and-deployment:start|7. Infrastructure and Deployment]] +
-  * [[dido:02-crusible:10-reproducibility-provenance-and-traceability:start|10. Reproducibility, Provenance, and Traceability]]+
  
 ===== Referenced By ===== ===== Referenced By =====
Line 212: Line 83:
 ===== Delivery Phase ===== ===== Delivery Phase =====
  
-Phase 1 and subsequent phases+Implemented and Verified.
  
 ===== Implementation Status ===== ===== Implementation Status =====
  
-Not Assessed +<todo>Assess whether the current Crucible implementation performs each Crucible operation allocated to the Developer Role.</todo>
- +
-Implementation status requires verification that the current [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] implementation executes each Crucible operation assigned to a Developer by the applicable operational scenario in response to the specified Developer interaction.+
  
 ===== Requirement Status ===== ===== Requirement Status =====
  
-Draft+<todo>Review and accept OR-001a as a proposed derived requirement created from the evaluation and decomposition of OR-001 in the Crucible System Requirements Specification, Version 1.1 Draft.</todo>
  
-This requirement derives from OR-001 in the Crucible System Requirements SpecificationVersion 1.1 Draft.+---- 
 +===== Issues ===== 
 + 
 +The following unresolved issues affect this requirement
 + 
 +<todo>Define Developer Role or reference an authoritative definition. Identify the essential characteristics of the role and distinguish the role from the DevSecOps Engineer Role, Platform Engineer Role, System Administrator RoleSecurity Engineer Role, and Compliance Officer Role.</todo> 
 + 
 +<todo>Identify the controlling source that allocates Crucible operations to the Developer Role.</todo>
  
 ---- ----
Line 232: Line 108:
  
 This page is a leaf requirement page and omits a trailing '':start'' from its namespace. This page is a leaf requirement page and omits a trailing '':start'' from its namespace.
 +
 +The parent OR-001 page is a non-leaf page and retains a trailing '':start'' in its namespace.
  
 Changes to the Statement should preserve: Changes to the Statement should preserve:
  
-  * Crucible as the responsible actor +  * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor 
-  * The Developer as the applicable user category +  * Developer Role as the recipient of the operation allocation 
-  * Assignment of the operation by the applicable operational scenario +  * Allocation of each Crucible operation to the Developer Role 
-  * Identification of the Developer interaction by the applicable operational scenario +  * Performance of each allocated operation by Crucible
-  * Execution of the assigned operation by Crucible+
  
-The requirement owner should confirm:+The unresolved meaning of Developer Role should remain recorded in the Issues section until an authoritative definition resolves the issue.
  
-  * Which Crucible operations apply to Developers +The source of each operation allocation should remain recorded in the Issues section until a controlling source establishes the allocation.
-  * Which operational scenarios assign those operations +
-  * Which Developer interaction applies to each operation +
-  * Which Developer inputs apply +
-  * Which outputs apply +
-  * Which existing requirements realize each assigned operation +
-  * Which uncovered interactions require additional atomic requirements+
  
-Material changes should receive review and should update the related verification criteria, requirements realization, related architecture sections, and source records.+Material changes should receive review and should update the verification criteria, source records, and Issues section.
  
 To reference this requirement Statement from another wiki page, insert: To reference this requirement Statement from another wiki page, insert:
  • dido/02-crusible/99-annexes/annex-c-requirements/02-operational-requirements/or-001/or-001a.1784652935.txt.gz
  • Last modified: 2026/07/21 09:55
  • by nick_dido