Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:start [2026/07/23 09:41] – removed - external edit (Unknown date) 127.0.0.1 | dido:02-crusible:99-annexes:annex-c-requirements:02-operational-requirements:or-003:start [2026/08/01 05:52] (current) – nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== OR-003 — Classified and Unclassified Environments ====== | ||
| + | [[dido: | ||
| + | |||
| + | ===== Original Requirement ===== | ||
| + | |||
| + | > //The system SHALL support classified and unclassified deployment environments.// | ||
| + | |||
| + | ===== Assessment of Original Requirement ===== | ||
| + | |||
| + | The Original Requirement preserves the approved operational intent but does not express independently testable normative statements. | ||
| + | |||
| + | The following Specification Discipline and Authoring findings apply: | ||
| + | |||
| + | * **The system** does not use the defined system name [[dido: | ||
| + | * **Support** is a weak verb that does not identify an observable behavior performed by Crucible | ||
| + | * **Classified and unclassified** combines two operating contexts that can pass or fail independently | ||
| + | * **Deployment environments** does not identify the Operational Lifecycle activities that Crucible performs | ||
| + | * The Original Requirement does not identify the [[dido: | ||
| + | * The Original Requirement does not identify the [[dido: | ||
| + | * The Original Requirement does not identify the [[dido: | ||
| + | * The Original Requirement does not require enforcement of access restrictions | ||
| + | * The Original Requirement does not require enforcement of [[dido: | ||
| + | * The Original Requirement does not identify the conditions governing movement of information between Security Domains | ||
| + | * The Original Requirement does not require use of an authorized [[dido: | ||
| + | * The Original Requirement does not identify the behavior required when information is not authorized for an operation or destination | ||
| + | * The Original Requirement does not provide independently identifiable statements for verification and Traceability | ||
| + | |||
| + | The previously normalized Statement also combined: | ||
| + | |||
| + | * Execution of selected Operational Lifecycle activities within Classified Environments | ||
| + | * Execution of selected Operational Lifecycle activities within Unclassified Environments | ||
| + | * Restriction of operations to the governing Security Domain | ||
| + | * Enforcement of access restrictions | ||
| + | * Enforcement of Information Handling Rules | ||
| + | * Control of information transfer between Security Domains | ||
| + | |||
| + | These obligations can pass or fail independently. | ||
| + | |||
| + | For example: | ||
| + | |||
| + | * Crucible can operate successfully in an Unclassified Environment and fail in a Classified Environment | ||
| + | * Crucible can enforce access restrictions and fail to enforce Information Handling Rules | ||
| + | * Crucible can operate within both environment types and permit an unauthorized Cross-Domain Transfer | ||
| + | * Crucible can enforce Security Domain boundaries for users while failing to restrict an automated process | ||
| + | * Crucible can reject an unauthorized transfer while failing to preserve the required transfer record | ||
| + | |||
| + | The Original Requirement therefore requires decomposition into independently identifiable normative requirements. | ||
| + | |||
| + | The decomposition preserves '' | ||
| + | |||
| + | The decomposition separates: | ||
| + | |||
| + | * Classified Environment operations | ||
| + | * Unclassified Environment operations | ||
| + | * Security Domain enforcement | ||
| + | * Information Handling Rule enforcement | ||
| + | * Cross-Domain Transfer control | ||
| + | * Security Domain access control | ||
| + | |||
| + | ===== Proposed Statements ===== | ||
| + | |||
| + | The Original Requirement is decomposed into the following proposed replacement requirements: | ||
| + | |||
| + | |||
| + | {{indexmenu> | ||
| + | |||
| + | ===== Requirement Status ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Issues ===== | ||
| + | |||
| + | The following unresolved issues affect the decomposition of OR-003: | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Notes for Editors ===== | ||
| + | |||
| + | This page should retain the stable parent requirement identifier '' | ||
| + | |||
| + | This page is a non-leaf requirement page and retains a trailing '': | ||
| + | |||
| + | The child requirements are leaf requirement pages and omit a trailing '': | ||
| + | |||
| + | The explicit child-page links should remain while the proposed decomposition is being developed. After the child pages have been created and finalized, the explicit links may be removed because the '' | ||
| + | |||
| + | This page preserves: | ||
| + | |||
| + | * The Original Requirement | ||
| + | * The assessment of the Original Requirement | ||
| + | * The reason for decomposition | ||
| + | * [[dido: | ||
| + | * The unresolved cross-cutting issues affecting the decomposition | ||
| + | * The supersession decision | ||
| + | |||
| + | The derived requirements should distinguish: | ||
| + | |||
| + | * Execution of Operational Lifecycle activities within [[dido: | ||
| + | * Execution of Operational Lifecycle activities within [[dido: | ||
| + | * Restriction of operations, resources, and information to the governing [[dido: | ||
| + | * Enforcement of [[dido: | ||
| + | * Control of information movement through authorized [[dido: | ||
| + | * Restriction of access according to identity, role, authorization, | ||
| + | |||
| + | The proposed child Statements should retain the following intent: | ||
| + | |||
| + | * OR-003a requires Crucible to execute selected Operational Lifecycle activities within a Classified Environment | ||
| + | * OR-003b requires Crucible to execute selected Operational Lifecycle activities within an Unclassified Environment | ||
| + | * OR-003c requires Crucible to restrict each operation to resources and information authorized for the governing Security Domain | ||
| + | * OR-003d requires Crucible to enforce the Information Handling Rules governing each information object processed by a Crucible operation | ||
| + | * OR-003e requires Crucible to transfer information between Security Domains only through an authorized Cross-Domain Transfer | ||
| + | * OR-003f requires Crucible to permit a user or process to access only operations, resources, and information authorized for its identity, role, and Security Domain | ||
| + | |||
| + | The Original Requirement should not be marked as superseded until the requirement owner: | ||
| + | |||
| + | * Approves the proposed decomposition | ||
| + | * Approves the child requirements | ||
| + | * Defines the Operational Lifecycle activities required in each environment type | ||
| + | * Defines the supported Security Domains | ||
| + | * Defines the governing Security Classifications and Classification Authorities | ||
| + | * Defines the Information Handling Rules | ||
| + | * Defines the authorized Cross-Domain Transfer mechanisms | ||
| + | * Defines the access-control model | ||
| + | * Confirms that the child requirements collectively preserve the complete approved intent of OR-003 | ||
| + | * Confirms that no additional child requirements are required | ||
| + | |||
| + | After supersession, | ||
| + | |||
| + | Material changes to the decomposition should update the child requirements, | ||
| + | |||
| + | ---- | ||
| + | |||
| + | <WRAP centeralign> | ||
| + | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. | ||
| + | </ | ||