dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001b

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001b [2026/07/22 07:43] – created nick_didodido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-001:or-001b [2026/07/30 05:30] (current) – [Delivery Phase] nick_dido
Line 5: Line 5:
 ===== Statement ===== ===== Statement =====
  
-[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform each Crucible operation invoked by a DevSecOps Engineer in accordance with the applicable operational scenario.+[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform each Crucible operation allocated to the DevSecOps Engineer Role.
  
 ===== Derived From ===== ===== Derived From =====
Line 23: Line 23:
 >> //Compliance Officers//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] >> //Compliance Officers//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
  
-OR-001b preserves the intent that DevSecOps Engineers participate in Crucible operation by requiring Crucible to perform each operation invoked by a DevSecOps Engineer in accordance with the applicable operational scenario.+OR-001b preserves the intent that DevSecOps Engineers participate in Crucible operation by requiring Crucible to perform each operation allocated to the DevSecOps Engineer Role.
  
 The separate requirements derived from OR-001 address: The separate requirements derived from OR-001 address:
Line 35: Line 35:
 ===== Rationale ===== ===== Rationale =====
  
-DevSecOps Engineers require access to the Crucible operations assigned to them by the applicable operational scenario.+DevSecOps Engineers require access to the Crucible operations allocated to the DevSecOps Engineer Role.
  
-This requirement ensures that Crucible performs each applicable operation invoked by a DevSecOps Engineer under the conditions defined for that operation.+This requirement ensures that Crucible performs each operation allocated to the DevSecOps Engineer Role.
  
-Separating DevSecOps Engineer operations from the operations associated with other user categories supports independent verification, [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]], and determination of whether Crucible satisfies the operational needs assigned to DevSecOps Engineers.+Separating DevSecOps Engineer operations from operations allocated to other user categories supports independent verification, [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]], and determination of whether Crucible satisfies the operational needs assigned to DevSecOps Engineers.
  
-Without this requirement, Crucible could perform operations for other user categories while failing to perform the operations required by DevSecOps Engineers.+Without this requirement, Crucible could perform operations allocated to other user categories while failing to perform the operations allocated to the DevSecOps Engineer Role.
  
 ===== Applies To ===== ===== Applies To =====
Line 49: Line 49:
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]
   * DevSecOps Engineers   * DevSecOps Engineers
-  * Operational scenarios applicable to DevSecOps Engineers +  * DevSecOps Engineer Role 
-  * Crucible operations identified for DevSecOps Engineers +  * Crucible operations allocated to the DevSecOps Engineer Role
-  * DevSecOps Engineer invocation of Crucible operations+
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]]   * [[dido:99_annexes:annex-b-terms-and-definitions:c:controlled_input|Controlled Inputs]]
   * Operation status   * Operation status
Line 69: Line 68:
 Verification confirms that: Verification confirms that:
  
-  - The applicable operational scenario identifies each Crucible operation that a DevSecOps Engineer can invoke +  - The DevSecOps Engineer Role is identified 
-  - The applicable operational scenario identifies the conditions under which the DevSecOps Engineer can invoke each operation +  - Each Crucible operation allocated to the DevSecOps Engineer Role is identified 
-  - The DevSecOps Engineer can invoke each identified Crucible operation under the specified conditions +  - Crucible performs each operation allocated to the DevSecOps Engineer Role 
-  - Crucible performs each operation invoked by the DevSecOps Engineer +  - The performed operation corresponds to the allocated operation 
-  - The performed operation corresponds to the operation invoked by the DevSecOps Engineer +  - Crucible produces each status, result, failure indication, exception indication, [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]][[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] item, or other output specified for the operation 
-  - Crucible produces each status, result, failure indication, exception indication, Artifact, Evidence item, or other output specified for the operation +  - The verification record preserves [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] between the DevSecOps Engineer Role, the allocated operation, and the performed operation
-  - The verification record preserves Traceability among the applicable operational scenario, the DevSecOps Engineer invocation, and the performed Crucible operation+
  
 ===== Referenced By ===== ===== Referenced By =====
Line 85: Line 83:
 ===== Delivery Phase ===== ===== Delivery Phase =====
  
-<todo>Determine the Delivery Phase applicable to OR-001b.</todo>+Implemented and Verified.
  
 ===== Implementation Status ===== ===== Implementation Status =====
  
-<todo>Assess whether the current Crucible implementation performs each Crucible operation invoked by a DevSecOps Engineer in accordance with the applicable operational scenario.</todo>+<todo>Assess whether the current Crucible implementation performs each Crucible operation allocated to the DevSecOps Engineer Role.</todo>
  
 ===== Requirement Status ===== ===== Requirement Status =====
Line 100: Line 98:
 The following unresolved issues affect this requirement: The following unresolved issues affect this requirement:
  
-<todo>Define DevSecOps Engineer or reference an authoritative definition. Clarify whether DevSecOps Engineer identifies a personuser categoryorganizational function, Operational Role, or another kind of actor.</todo>+<todo>Define DevSecOps Engineer Role or reference an authoritative definition. Identify the essential characteristics of the role and distinguish the role from the Developer Role, Platform Engineer RoleSystem Administrator RoleSecurity Engineer Role, and Compliance Officer Role.</todo>
  
-<todo>Distinguish DevSecOps Engineer from Developer, Platform Engineer, System Administrator, Security Engineer, and Compliance Officer.</todo>+<todo>Identify the controlling source that allocates Crucible operations to the DevSecOps Engineer Role.</todo>
  
 ---- ----
Line 116: Line 114:
  
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] as the responsible actor
-  * DevSecOps Engineer as the applicable user category +  * DevSecOps Engineer Role as the recipient of the operation allocation 
-  * The applicable operational scenario as the source of the operational context +  * Allocation of each Crucible operation to the DevSecOps Engineer Role 
-  * Invocation of the operation by the DevSecOps Engineer +  * Performance of each allocated operation by Crucible
-  * Performance of the invoked operation by Crucible+
  
-The unresolved meaning of DevSecOps Engineer should remain recorded in the Issues section until an authoritative definition or classification resolves the issue.+The unresolved meaning of DevSecOps Engineer Role should remain recorded in the Issues section until an authoritative definition resolves the issue
 + 
 +The source of each operation allocation should remain recorded in the Issues section until a controlling source establishes the allocation.
  
 Material changes should receive review and should update the verification criteria, source records, and Issues section. Material changes should receive review and should update the verification criteria, source records, and Issues section.
  • dido/02-crusible/99-annexes/annex-c-requirements/02-operational-requirements/or-001/or-001b.1784731437.txt.gz
  • Last modified: 2026/07/22 07:43
  • by nick_dido