dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001a

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001a [2026/07/21 10:20] – ToDo unchecked: Define **Developer** or reference an authoritative definition. Clarify whether Developer identifies a person, user category, organizational function, Operational Role, or another kind of actor. nick_didodido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001a [2026/07/30 05:30] (current) – [Delivery Phase] nick_dido
Line 5: Line 5:
 ===== Statement ===== ===== Statement =====
  
-[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL execute each Crucible operation allocated to Developer by the applicable Operational Scenario upon receipt of the initiating input specified by that Operational Scenario.+[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform each Crucible operation allocated to the Developer Role.
  
 ===== Derived From ===== ===== Derived From =====
Line 23: Line 23:
 >> //Compliance Officers//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] >> //Compliance Officers//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
  
-OR-001a preserves the intent that Developers participate in Crucible operation by requiring Crucible to execute each operation allocated to a Developer by the applicable Operational Scenario.+OR-001a preserves the intent that Developers participate in Crucible operation by requiring Crucible to perform each operation allocated to the Developer Role.
  
 The separate requirements derived from OR-001 address: The separate requirements derived from OR-001 address:
Line 32: Line 32:
   * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001e|OR-001e — Security Engineer Operations]]   * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001e|OR-001e — Security Engineer Operations]]
   * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001f|OR-001f — Compliance Officer Operations]]   * [[dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001f|OR-001f — Compliance Officer Operations]]
- 
-===== Assessment ===== 
- 
-The Original Requirement identifies Developers as a user category that participates in Crucible operation but does not identify: 
- 
-  * The meaning of Developer 
-  * The characteristics that distinguish a Developer from the other listed user categories 
-  * The Crucible operations allocated to a Developer 
-  * The Operational Scenarios in which a Developer participates 
-  * The initiating input associated with each allocated operation 
-  * The interfaces through which a Developer provides the initiating input 
-  * The inputs required for each operation 
-  * The outputs produced for each operation 
-  * The completion conditions for each operation 
-  * The failure and exception conditions for each operation 
-  * The [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] required to demonstrate execution of each operation 
- 
-The phrase **support operation by Developers** does not identify an observable Crucible behavior. 
- 
-OR-001a: 
- 
-  * Identifies [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor 
-  * Separates Developer participation from participation by the other listed user categories 
-  * Requires the applicable Operational Scenario to allocate the Crucible operation to a Developer 
-  * Requires the applicable Operational Scenario to identify the initiating input 
-  * Requires Crucible to execute the allocated operation upon receipt of the specified initiating input 
- 
-OR-001a does not establish: 
- 
-  * A definition of Developer 
-  * That every Crucible operation applies to a Developer 
-  * That every Developer participates in the same Crucible operations 
-  * That every Operational Scenario allocates the same operations to a Developer 
-  * A role-assignment mechanism 
-  * A role-based authorization model 
-  * A particular access-control model 
-  * A particular interface 
-  * A particular form of initiating input 
-  * Permissions not established by another controlling requirement 
  
 ===== Rationale ===== ===== Rationale =====
  
-Separating Developer operations from operations associated with the other listed user categories provides an independently testable and traceable requirement. +Developers require access to the Crucible operations allocated to the Developer Role.
- +
-The applicable Operational Scenario provides the context required to determine: +
- +
-  * Which Crucible operations apply to Developer +
-  * Which initiating input applies to each operation +
-  * Which interfaces receive the initiating input +
-  * Which additional inputs apply +
-  * Which outputs Crucible produces +
-  * Which completion conditions apply +
-  * Which failure and exception conditions apply +
-  * Which [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] and [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] demonstrate execution of the operation +
- +
-The [[dido:02-crusible:99-annexes:annex-b:cr-002|Crucible Concept of Operations [C2]]] identifies Build, Capture, and Deploy as high-level Crucible operations. +
- +
-The Concept of Operations does not identify:+
  
-  * Which of these operations apply to a Developer +This requirement ensures that Crucible performs each operation allocated to the Developer Role.
-  * Whether additional Crucible operations apply to a Developer +
-  * How a Developer participates in each operation +
-  * Which initiating input applies to each operation+
  
-The applicable Operational Scenario must identify these allocations and interactions.+Separating Developer operations from operations allocated to other user categories supports independent verification, [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]], and determination of whether Crucible satisfies the operational needs assigned to Developers.
  
-This requirement does not define the internal behavior of BuildCapture, Deploy, or another Crucible operation. Separate functional and operational requirements define those behaviors.+Without this requirement, Crucible could perform operations allocated to other user categories while failing to perform the operations allocated to the Developer Role.
  
 ===== Applies To ===== ===== Applies To =====
Line 106: Line 49:
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]
   * Developers   * Developers
-  * Applicable Operational Scenarios +  * Developer Role 
-  * Crucible operations allocated to Developers +  * Crucible operations allocated to the Developer Role 
-  * Initiating inputs specified for Developer operations +  * [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]]
-  * Interfaces that receive Developer inputs+
   * Operation status   * Operation status
   * Operation results   * Operation results
Line 118: Line 60:
   * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]   * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]   * [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environments]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]
  
 ===== Verification ===== ===== Verification =====
Line 123: Line 68:
 Verification confirms that: Verification confirms that:
  
-  The applicable Operational Scenario identifies the Developer +  The Developer Role is identified 
-  # The applicable Operational Scenario identifies each Crucible operation allocated to the Developer +  - Each Crucible operation allocated to the Developer Role is identified 
-  # The applicable Operational Scenario identifies the initiating input for each allocated operation +  - Crucible performs each operation allocated to the Developer Role 
-  # Crucible receives the initiating input specified for the allocated operation +  The performed operation corresponds to the allocated operation 
-  # Crucible executes the operation allocated to the Developer +  Crucible produces each status, result, failure indication, exception indication, [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]][[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] item, or other output specified for the operation 
-  The executed operation corresponds to the operation identified by the applicable Operational Scenario +  - The verification record preserves [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] between the Developer Role, the allocated operation, and the performed operation
-  Crucible produces each status, result, failure indication, exception indication, Artifact, Evidence item, or other output specified for the operation +
-  # The verification record preserves Traceability among the applicable Operational Scenario, the Developer, the initiating input, and the executed operation +
- +
-Verification includes: +
- +
-  * Inspection of the applicable Operational Scenario +
-  * Inspection of the operation allocation +
-  * Inspection of the specified initiating input +
-  * Submission of the specified initiating input +
-  * Observation of Crucible execution +
-  * Inspection of operation status +
-  * Inspection of operation results +
-  * Failure-condition testing +
-  * Exception-condition testing +
-  * Artifact inspection +
-  * Evidence inspection +
-  * Provenance inspection +
-  * Traceability inspection +
- +
-The verification record identifies: +
- +
-  # The applicable Operational Scenario +
-  # The Developer +
-  # The allocated Crucible operation +
-  # The specified initiating input +
-  # The interface that received the initiating input +
-  # The executed Crucible operation +
-  # The operation start condition +
-  # The operation completion condition +
-  # Each generated status or result +
-  # Each observed failure or exception +
-  # Each generated [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]] +
-  # The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] +
-  # The associated [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] +
-  # The associated [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] +
- +
-===== Requirements Realized By ===== +
- +
-No realizing requirements have been identified. +
- +
-===== Related Architecture Sections ===== +
- +
-No related architecture sections have been identified.+
  
 ===== Referenced By ===== ===== Referenced By =====
Line 181: Line 83:
 ===== Delivery Phase ===== ===== Delivery Phase =====
  
-To Be Determined+Implemented and Verified.
  
 ===== Implementation Status ===== ===== Implementation Status =====
  
-Not Assessed +<todo>Assess whether the current Crucible implementation performs each Crucible operation allocated to the Developer Role.</todo>
- +
-Implementation status requires verification that the current [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] implementation executes each Crucible operation allocated to Developer upon receipt of the initiating input specified by the applicable Operational Scenario.+
  
 ===== Requirement Status ===== ===== Requirement Status =====
  
-Draft +<todo>Review and accept OR-001a as a proposed derived requirement created from the evaluation and decomposition of OR-001 in the Crucible System Requirements Specification, Version 1.1 Draft.</todo>
- +
-This requirement derives from OR-001 in the Crucible System Requirements Specification, Version 1.1 Draft.+
  
 +----
 ===== Issues ===== ===== Issues =====
  
 The following unresolved issues affect this requirement: The following unresolved issues affect this requirement:
  
-  * <todo>Define **Developer** or reference an authoritative definition. Clarify whether Developer identifies a personuser categoryorganizational functionOperational Role, or another kind of actor.</todo>+<todo>Define Developer Role or reference an authoritative definition. Identify the essential characteristics of the role and distinguish the role from the DevSecOps Engineer RolePlatform Engineer RoleSystem Administrator RoleSecurity Engineer Role, and Compliance Officer Role.</todo>
  
-  * <todo>Distinguish **Developer** from **DevSecOps Engineer**, **Platform Engineer**, **System Administrator**, **Security Engineer**, and **Compliance Officer**.</todo> +<todo>Identify the controlling source that allocates Crucible operations to the Developer Role.</todo>
- +
-  * <todo>Determine whether **Operational Scenario** and **Crucible operation** require controlling Terms and Definitions entries.</todo> +
- +
-  * <todo>Identify the Crucible operations allocated to a Developer in each applicable Operational Scenario.</todo> +
- +
-  * <todo>Identify how a Developer participates in each allocated Crucible operation.</todo> +
- +
-  * <todo>Identify the initiating input, interface, additional inputs, outputs, completion conditions, failures, exceptions, Artifacts, and Evidence applicable to each Developer operation.</todo> +
- +
-  * <todo>Determine whether existing requirements already define each applicable Developer interaction and create additional atomic requirements only for confirmed coverage gaps.</todo> +
- +
-  * <todo>Identify the requirements that realize OR-001a.</todo> +
- +
-  * <todo>Identify the architecture sections related to OR-001a.</todo> +
- +
-  * <todo>Confirm the Delivery Phase for OR-001a.</todo>+
  
 ---- ----
Line 231: Line 114:
  
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor
-  * Developer as the applicable user category +  * Developer Role as the recipient of the operation allocation 
-  * Allocation of the operation by the applicable Operational Scenario +  * Allocation of each Crucible operation to the Developer Role 
-  * Identification of the initiating input by the applicable Operational Scenario +  * Performance of each allocated operation by Crucible 
-  * Execution of the allocated operation by Crucible+ 
 +The unresolved meaning of Developer Role should remain recorded in the Issues section until an authoritative definition resolves the issue.
  
-The unresolved meaning of Developer should remain recorded in the Issues section until an authoritative definition or classification resolves the issue.+The source of each operation allocation should remain recorded in the Issues section until a controlling source establishes the allocation.
  
-Material changes should receive review and should update the verification criteria, requirements realization, related architecture sections, source records, and Issues section.+Material changes should receive review and should update the verification criteria, source records, and Issues section.
  
 To reference this requirement Statement from another wiki page, insert: To reference this requirement Statement from another wiki page, insert:
  • dido/02-crusible/99-annexes/annex-c-requirements/02-operational-requirements/or-001/or-001a.1784654453.txt.gz
  • Last modified: 2026/07/21 10:20
  • by nick_dido