dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002 [2026/07/18 09:19] – created nick_didodido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002 [2026/07/30 05:57] (current) nick_dido
Line 5: Line 5:
 ===== Statement ===== ===== Statement =====
  
-[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL create an Artifact Export Package containing identified [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] and the metadata required to transfer those Artifacts across a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundary]].+[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL create [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundles]] for export.
  
-===== Source Statement =====+===== Derived From =====
  
-> The system shall support artifact export packages.+This requirement derives from:
  
-===== Source =====+  * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-002
  
-Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-002.+The Original Requirement states:
  
-===== Assessment =====+> //The system shall support artifact export packages.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
  
-The source statement identifies a required package type but does not state the required package-creation behavior.+FR-AG-002:
  
-The following Specification Discipline and Authoring findings apply:+  * Replaces **The system** with the defined system name [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] 
 +  * Changes **shall** to the established uppercase normative form **SHALL** 
 +  * Replaces the weak verb **support** with the observable behavior **create** 
 +  * Maps **artifact export packages** to the defined [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] concept
  
-  * **The system** does not use the defined system name +No other substantive normalization is required.
-  * **shall** does not follow the established uppercase normative convention +
-  * **Support** is a weak verb +
-  * **Artifact export packages** does not identify whether Crucible creates, validates, transfers, or consumes the package +
-  * The source statement does not identify the package contents +
-  * The source statement does not identify the transfer context +
-  * The source statement does not prescribe a package format, archive technology, storage medium, transfer mechanism, or cryptographic mechanism +
- +
-The normalized Statement: +
- +
-  * Replaces **The system** with [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] +
-  * Replaces **support** with the direct behavior **create** +
-  * Identifies the included Artifacts +
-  * Requires metadata needed for transfer +
-  * Identifies a Transfer Boundary as the transfer context +
-  * Preserves implementation independence +
-  * Retains one primary required behavior +
- +
-**Artifact Export Package** should receive a glossary definition because it identifies a distinct transfer artifact.+
  
 ===== Rationale ===== ===== Rationale =====
  
-An Artifact Export Package groups the Artifacts and associated metadata required for controlled transfer from one environment to another.+A [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] provides a controlled package for exporting [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] and related information from one environment for transfer to another environment.
  
-The package may contain:+A Transfer Bundle can contain:
  
   * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]]   * [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Images]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:container_image|Container Images]]   * [[dido:99_annexes:annex-b-terms-and-definitions:c:container_image|Container Images]]
-  * Infrastructure configurations +  * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_configuration|Infrastructure Configurations]] 
-  * Baseline records +  * [[dido:99_annexes:annex-b-terms-and-definitions:b:baseline|Baselines]]
-  * Deployment configurations+
   * Software packages   * Software packages
-  * Dependency artifacts +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependencies]] 
-  * Compliance evidence +  * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] 
-  * Digital signatures+  * [[dido:99_annexes:annex-b-terms-and-definitions:d:digital_signature|Digital Signatures]]
   * Content digests   * Content digests
   * Manifests   * Manifests
-  * Provenance records +  * Provenance information 
-  * Traceability records +  * Traceability information
-  * Import instructions+
  
-The associated metadata may identify:+This requirement establishes creation of Transfer Bundles for export without prescribing:
  
-  * Package identifier +  * The Artifacts included in a particular Transfer Bundle 
-  * Package revision +  * The Transfer Bundle format 
-  * Included Artifacts +  * The storage medium 
-  * Artifact identifiers +  * The transfer mechanism 
-  * Artifact revisions +  * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_authorization|Transfer Authorization]] 
-  * Artifact content digests +  * Transfer across a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundary]] 
-  * Source environment +  * Verification of [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle_integrity|Transfer Bundle Integrity]] 
-  * Intended destination environment +  * Import of the Transfer Bundle 
-  * Transfer authorization +  * Approval, promotion, or deployment of included Artifacts 
-  * Integrity information +  * A requirement that export and import use the same package identity
-  * Creation time +
-  * Creating actor or process +
-  * Applicable Baseline+
  
-FR-AG-002 requires package creation. Separate requirements govern transfer authorizationtransportpackage-integrity verification, and import.+Separate requirements, architecture specificationsworkflowsor policies define those subjects and behaviors.
  
 ===== Applies To ===== ===== Applies To =====
Line 85: Line 65:
  
   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]   * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]]
-  * Artifact Export Packages +  * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundles]] 
-  * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] +  * Artifact export operations
-  * Package manifests +
-  * Artifact identifiers +
-  * Artifact revisions +
-  * Content digests +
-  * Digital signatures +
-  * Transfer metadata +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundaries]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_authorization|Transfer Authorizations]]+
  
 ===== Verification ===== ===== Verification =====
  
-  - Verification SHALL confirm that the Artifacts selected for export are identified +Verification confirms that:
-  - Verification SHALL confirm that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] creates an Artifact Export Package +
-  - Verification SHALL confirm that the package contains the identified Artifacts +
-  - Verification SHALL confirm that the package contains the metadata required for transfer across the applicable [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundary]]+
  
-Verification may include: +  One or more [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] are selected for export 
- +  - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] creates a [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] for the tested export 
-  * Export-package creation testing +  - The created Transfer Bundle contains or references the selected Artifacts 
-  * Package-content inspection +  - The resulting Transfer Bundle can be identified as the output of the tested export-package operation
-  * Manifest inspection +
-  * Artifact identifier comparison +
-  * Artifact revision comparison +
-  * Content-digest comparison +
-  * Transfer-metadata inspection +
- +
-The verification record SHALL identify: +
- +
-  - The Artifact Export Package +
-  - The included Artifacts +
-  - The package manifest +
-  - The Artifact identifiers +
-  - The Artifact revisions +
-  - The applicable Transfer Boundary +
-  - The transfer metadata +
-  - The export result +
-  - The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] +
- +
-===== Outgoing Traceability ===== +
- +
-This requirement realizes: +
- +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004|MO-004]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-006|MO-006]] +
- +
-This requirement relates to: +
- +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001|FR-AG-001 — Disconnected Deployment Operations]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003|FR-AG-003 — Artifact Import Packages]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-005|FR-AG-005 — Deployment Traceability Across Disconnected Environments]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-10-dependency-capture-and-offline-transfer:start|C.3.10 Dependency Capture and Offline Transfer]] +
-  * [[dido:02-crusible:08-dependencies-and-air-gap-operations:start|8. Dependencies and Air Gap Operations]]+
  
 ===== Referenced By ===== ===== Referenced By =====
  
-The wiki Backlinks function provides the current list of pages that reference ''FR-AG-002''.+The following pages reference this requirement:
  
-Incoming Traceability should be derived dynamically from backlinks rather than maintained as a duplicate manual list.+{{backlinks>.#dido:02-crusible}}
  
-===== ConOps Relationship =====+===== Implementation Status =====
  
-The Crucible Concept of Operations describes packaging captured Artifacts and dependencies for authorized transfer from a Connected Environment to a Disconnected Environment.+Implemented and Verified
  
-FR-AG-002 establishes the required package-creation behavior for that supply chain.+===== Requirement Status =====
  
-===== Delivery Phase =====+<todo>Review and approve FR-AG-002 as a leaf requirement.</todo>
  
-Phase 1+---- 
 +===== Issues =====
  
-===== Implementation Status ===== +<todo>Determine whether separate requirements define the minimum required contents and metadata of a Transfer Bundle.</todo>
- +
-Not Assessed +
- +
-===== Requirement Status =====+
  
-Draft+<todo>Determine whether export and import must preserve one Transfer Bundle identity or may create distinct package records.</todo>
  
 ---- ----
 ===== Notes for Editors ===== ===== Notes for Editors =====
  
-This requirement page should retain the stable requirement identifier ''FR-AG-002''.+This requirement page retains the stable requirement identifier ''FR-AG-002''.
  
-Changes to the Statement SHALL preserve the approved intent of the source requirement.+This page is a leaf requirement page and omits a trailing '':start'' from its namespace.
  
-The Statement should remain limited to creation of an Artifact Export Package containing identified Artifacts and required transfer metadata.+The source phrase **artifact export packages** maps to the defined [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]] concept.
  
-Requirements for transport, Transfer Authorization, package integrity verification, and import should remain separate.+The Statement preserves the approved source intent by requiring Crucible to create Transfer Bundles for export. 
 + 
 +Do not introduce separate **Artifact Export Package** and **Artifact Import Package** concepts unless the controlling architecture defines different package structures or identities. 
 + 
 +Do not add Transfer Authorization, transfer, integrity verification, import, approval, promotion, deployment, or cross-environment identity-preservation obligations unless the controlling requirement changes through an approved requirements process.
  
 To reference this requirement Statement from another wiki page, insert: To reference this requirement Statement from another wiki page, insert:
Line 180: Line 118:
 {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002#Statement&noheader&nofooter&noeditbtn}} {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002#Statement&noheader&nofooter&noeditbtn}}
 </code> </code>
- 
-Do not rename this page after an external citation unless a redirect or move plan is in place. 
  
 ---- ----
  • dido/02-crusible/99-annexes/annex-c-requirements/03-functional-requirements/03-05-air-gap-operations/fr-ag-002.1784391582.txt.gz
  • Last modified: 2026/07/18 09:19
  • by nick_dido