dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003a

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003a [2026/07/23 09:40] – created nick_didodido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:or-003a [2026/07/30 05:33] (current) – [Delivery Phase] nick_dido
Line 22: Line 22:
 ===== Rationale ===== ===== Rationale =====
  
-A Classified Environment imposes authorization, access, information-handling, transfer, auditing, and operational constraints that can differ from those governing an Unclassified Environment. +[[dido:99_annexes:annex-b-terms-and-definitions:c:classified_environment|Classified Environment]] imposes authorization, access, information-handling, transfer, auditing, and operational constraints that differ from those governing an [[dido:99_annexes:annex-b-terms-and-definitions:u:unclassified_environment|Unclassified Environment]].
- +
-Crucible must execute its selected Operational Lifecycle activities within those constraints rather than treating classified operation as an extension of ordinary deployment. +
- +
-Selected Operational Lifecycle activities can include: +
- +
-  * Description retrieval +
-  * Baseline composition +
-  * Dependency acquisition or import +
-  * Machine Image construction +
-  * Security hardening +
-  * Compliance assessment +
-  * Infrastructure Deployment +
-  * Deployment Validation +
-  * Evidence generation +
-  * Maintenance +
-  * Update +
-  * Cross-Domain Transfer +
-  * Retirement +
- +
-The governing requirements for a Classified Environment can depend on: +
- +
-  * The authorized [[dido:99_annexes:annex-b-terms-and-definitions:s:security_classification|Security Classification]] +
-  * The governing [[dido:99_annexes:annex-b-terms-and-definitions:s:security_domain|Security Domain]] +
-  * The responsible [[dido:99_annexes:annex-b-terms-and-definitions:c:classification_authority|Classification Authority]] +
-  * Access restrictions +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:i:information_handling_rules|Information Handling Rules]] +
-  * Authorized [[dido:99_annexes:annex-b-terms-and-definitions:c:cross-domain_transfer|Cross-Domain Transfer]] mechanisms +
-  * Security and Compliance Baselines +
-  * Connectivity restrictions +
-  * Audit and Evidence requirements +
- +
-OR-003a establishes the requirement to execute the selected activities within a Classified Environment. Separate requirements govern Security Domain enforcement, Information Handling Rule enforcement, Cross-Domain Transfer control, and access control.+
  
 +OR-003a requires [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] to execute selected [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] activities within the classified operating context rather than treating classified operation as an extension of unclassified operation.
 ===== Applies To ===== ===== Applies To =====
  
Line 104: Line 73:
 ===== Delivery Phase ===== ===== Delivery Phase =====
  
-<todo>Determine the Delivery Phase for OR-003a.</todo>+Implemented and Verified.
  
 ===== Implementation Status ===== ===== Implementation Status =====
  • dido/02-crusible/99-annexes/annex-c-requirements/02-operational-requirements/or-003/or-003a.1784824807.txt.gz
  • Last modified: 2026/07/23 09:40
  • by nick_dido