dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002

This is an old revision of the document!


FR-AG-002 — Artifact Export Packages

Crucible SHALL create an Artifact Export Package containing identified Artifacts and the metadata required to transfer those Artifacts across a Transfer Boundary.

The system shall support artifact export packages.

Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-002.

The source statement identifies a required package type but does not state the required package-creation behavior.

The following Specification Discipline and Authoring findings apply:

  • The system does not use the defined system name
  • shall does not follow the established uppercase normative convention
  • Support is a weak verb
  • Artifact export packages does not identify whether Crucible creates, validates, transfers, or consumes the package
  • The source statement does not identify the package contents
  • The source statement does not identify the transfer context
  • The source statement does not prescribe a package format, archive technology, storage medium, transfer mechanism, or cryptographic mechanism

The normalized Statement:

  • Replaces The system with Crucible
  • Replaces support with the direct behavior create
  • Identifies the included Artifacts
  • Requires metadata needed for transfer
  • Identifies a Transfer Boundary as the transfer context
  • Preserves implementation independence
  • Retains one primary required behavior

Artifact Export Package should receive a glossary definition because it identifies a distinct transfer artifact.

An Artifact Export Package groups the Artifacts and associated metadata required for controlled transfer from one environment to another.

The package may contain:

  • Infrastructure configurations
  • Baseline records
  • Deployment configurations
  • Software packages
  • Dependency artifacts
  • Compliance evidence
  • Digital signatures
  • Content digests
  • Manifests
  • Provenance records
  • Traceability records
  • Import instructions

The associated metadata may identify:

  • Package identifier
  • Package revision
  • Included Artifacts
  • Artifact identifiers
  • Artifact revisions
  • Artifact content digests
  • Source environment
  • Intended destination environment
  • Transfer authorization
  • Integrity information
  • Creation time
  • Creating actor or process
  • Applicable Baseline

FR-AG-002 requires package creation. Separate requirements govern transfer authorization, transport, package-integrity verification, and import.

This requirement applies to:

  1. Verification SHALL confirm that the Artifacts selected for export are identified
  2. Verification SHALL confirm that Crucible creates an Artifact Export Package
  3. Verification SHALL confirm that the package contains the identified Artifacts
  4. Verification SHALL confirm that the package contains the metadata required for transfer across the applicable Transfer Boundary

Verification may include:

  • Export-package creation testing
  • Package-content inspection
  • Manifest inspection
  • Artifact identifier comparison
  • Artifact revision comparison
  • Content-digest comparison
  • Transfer-metadata inspection

The verification record SHALL identify:

  1. The Artifact Export Package
  2. The included Artifacts
  3. The package manifest
  4. The Artifact identifiers
  5. The Artifact revisions
  6. The applicable Transfer Boundary
  7. The transfer metadata
  8. The export result
  9. The generated Evidence

The wiki Backlinks function provides the current list of pages that reference FR-AG-002.

Incoming Traceability should be derived dynamically from backlinks rather than maintained as a duplicate manual list.

The Crucible Concept of Operations describes packaging captured Artifacts and dependencies for authorized transfer from a Connected Environment to a Disconnected Environment.

FR-AG-002 establishes the required package-creation behavior for that supply chain.

Phase 1

Not Assessed

Draft


This requirement page should retain the stable requirement identifier FR-AG-002.

Changes to the Statement SHALL preserve the approved intent of the source requirement.

The Statement should remain limited to creation of an Artifact Export Package containing identified Artifacts and required transfer metadata.

Requirements for transport, Transfer Authorization, package integrity verification, and import should remain separate.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/03-functional-requirements/03-05-air-gap-operations/fr-ag-002.1784391582.txt.gz
  • Last modified: 2026/07/18 09:19
  • by nick_dido