dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003

This is an old revision of the document!


FR-AG-003 — Artifact Import Packages

Crucible SHALL import the identified Artifacts contained in an authorized Artifact Import Package after verifying the package integrity.

The system shall support artifact import packages.

Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-003.

The source statement identifies a required package type but does not state the required import behavior.

The following Specification Discipline and Authoring findings apply:

  • The system does not use the defined system name
  • shall does not follow the established uppercase normative convention
  • Support is a weak verb
  • Artifact import packages does not identify whether Crucible creates, validates, stores, or consumes the package
  • The source statement does not identify whether the package must be authorized
  • The source statement does not identify whether package integrity must be verified before import
  • The source statement does not prescribe a package format, archive technology, storage medium, or integrity mechanism

The normalized Statement:

  • Replaces The system with Crucible
  • Replaces support with the direct behavior import
  • Identifies the Artifacts as the imported subjects
  • Requires package authorization
  • Requires package-integrity verification before import
  • Preserves implementation independence

This normalization relies on the established concepts of Transfer Authorization and Transfer Bundle Integrity.

Artifact Import Package should receive a glossary definition. It may be the destination-environment role of the same transferable package created as an Artifact Export Package rather than a structurally different package type.

An Artifact Import Package supplies Artifacts and metadata to a destination environment after controlled transfer.

The import process may:

  • Read the package manifest
  • Identify the included Artifacts
  • Verify package integrity
  • Verify Artifact content digests
  • Verify Digital Signatures
  • Confirm Transfer Authorization
  • Reject unauthorized or invalid content
  • Place accepted Artifacts into local repositories
  • Register Artifact identifiers and revisions
  • Preserve provenance and traceability records

A package created as an Artifact Export Package may become an Artifact Import Package when the destination environment receives and processes it.

FR-AG-003 does not independently authorize the imported Artifacts for deployment or operation. Separate approval, promotion, compliance, and deployment requirements govern those decisions.

This requirement applies to:

  1. Verification SHALL confirm that the Artifact Import Package is authorized
  2. Verification SHALL confirm that Crucible verifies the package integrity before importing its contents
  3. Verification SHALL confirm that Crucible imports the identified Artifacts contained in a valid authorized package
  4. Verification SHALL confirm that Crucible does not import the tested package when authorization or package-integrity verification fails

Verification may include:

  • Authorized-package import testing
  • Unauthorized-package testing
  • Modified-package testing
  • Manifest inspection
  • Content-digest comparison
  • Digital-signature verification
  • Local repository inspection
  • Import-log inspection

The verification record SHALL identify:

  1. The Artifact Import Package
  2. The included Artifacts
  3. The Transfer Authorization
  4. The package-integrity verification result
  5. The imported Artifact identifiers
  6. The imported Artifact revisions
  7. The destination repository
  8. The import result
  9. The generated Evidence

The wiki Backlinks function provides the current list of pages that reference FR-AG-003.

Incoming Traceability should be derived dynamically from backlinks rather than maintained as a duplicate manual list.

The Crucible Concept of Operations describes receipt, integrity verification, and import of transferred Artifacts into a Disconnected Environment.

FR-AG-003 establishes the required import behavior for authorized Artifact packages.

Phase 1

Not Assessed

Draft


This requirement page should retain the stable requirement identifier FR-AG-003.

Changes to the Statement SHALL preserve the approved intent of the source requirement.

The Statement should remain limited to importing identified Artifacts from an authorized package after package-integrity verification.

Requirements for package creation, physical transfer, Artifact approval, Image Promotion, and deployment should remain separate.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/03-functional-requirements/03-05-air-gap-operations/fr-ag-003.1784392334.txt.gz
  • Last modified: 2026/07/18 09:32
  • by nick_dido