dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-005

This is an old revision of the document!


FR-AG-005 — Deployment Traceability Across Disconnected Environments

Crucible SHALL preserve the traceability relationships that connect a deployment performed in a Disconnected Environment to its source Baseline, transferred Artifacts, deployment inputs, and deployment results.

The system shall maintain deployment traceability across disconnected environments.

Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-005.

The source statement uses a direct verb but does not identify the subjects that must remain traceable.

The following Specification Discipline and Authoring findings apply:

  • The system does not use the defined system name
  • shall does not follow the established uppercase normative convention
  • Maintain does not identify which traceability relationships must be preserved
  • Across disconnected environments may imply direct communication even though the environments may not have network connectivity
  • The source statement does not identify the source Baseline, transferred Artifacts, deployment inputs, or deployment results
  • The source statement does not prescribe a traceability data model, repository, identifier format, transfer mechanism, or implementation technology

The normalized Statement:

  • Replaces The system with Crucible
  • Replaces the broad verb maintain with preserve
  • Identifies the deployment as the traceability subject
  • Identifies the source Baseline
  • Identifies the transferred Artifacts
  • Identifies the deployment inputs and deployment results
  • Does not assume direct network connectivity
  • Preserves implementation independence

The normalized Statement does not require a centralized traceability repository. Traceability records may travel with exported and imported packages and may be retained independently within each environment.

Disconnected transfer must not sever the relationships that establish what was built, approved, transferred, imported, and deployed.

Deployment traceability may connect:

  • A deployment identifier
  • A source Baseline
  • Baseline Revision
  • Baseline Composition
  • Included Artifact identifiers
  • Included Artifact Revisions
  • Artifact content digests
  • Artifact Export Package identifier
  • Transfer Authorization
  • Artifact Import Package identifier
  • Destination environment
  • Deployment inputs
  • Deployment operation
  • Deployment result
  • Deployment Validation result
  • Compliance findings
  • Generated Evidence

Preserving these relationships allows an evaluator to determine whether the deployment performed in a Disconnected Environment corresponds to the approved and transferred source material.

Traceability preservation differs from synchronization:

  • Synchronization preserves the controlled content and identity of a Baseline
  • Traceability preservation retains the relationships among the Baseline, transfer records, deployment inputs, and deployment results

This requirement applies to:

  1. Verification SHALL confirm that the tested deployment has an identified deployment record
  2. Verification SHALL confirm that the deployment record identifies the source Baseline
  3. Verification SHALL confirm that the deployment record identifies the transferred Artifacts
  4. Verification SHALL confirm that the deployment record identifies the deployment inputs
  5. Verification SHALL confirm that the deployment record identifies the deployment results
  6. Verification SHALL confirm that the traceability relationships remain available within the Disconnected Environment without access to a Connected Environment

Verification may include:

  • Deployment-record inspection
  • Baseline traceability inspection
  • Artifact manifest comparison
  • Export-package record inspection
  • Import-package record inspection
  • Deployment-input comparison
  • Deployment-result comparison
  • Identifier continuity testing
  • Disconnected traceability demonstrations

The verification record SHALL identify:

  1. The deployment identifier
  2. The Disconnected Environment
  3. The source Baseline
  4. The Baseline Revision
  5. The transferred Artifacts
  6. The Artifact Export Package
  7. The Transfer Authorization
  8. The Artifact Import Package
  9. The deployment inputs
  10. The deployment results
  11. The preserved traceability relationships
  12. The generated Evidence

The wiki Backlinks function provides the current list of pages that reference FR-AG-005.

Incoming Traceability should be derived dynamically from backlinks rather than maintained as a duplicate manual list.

The Crucible Concept of Operations describes a connected-to-disconnected supply chain in which build, compliance, dependency, transfer, import, and deployment records remain associated with the Artifacts they describe.

FR-AG-005 preserves those relationships after the deployment enters and operates within a Disconnected Environment.

Phase 1

Not Assessed

Draft


This requirement page should retain the stable requirement identifier FR-AG-005.

Changes to the Statement SHALL preserve the approved intent of the source requirement.

The Statement should remain limited to preservation of traceability relationships connecting a disconnected deployment to its source Baseline, transferred Artifacts, deployment inputs, and deployment results.

The requirement should not imply that Connected and Disconnected Environments maintain direct network communication.

Verification criteria should test only the behavior stated in the normalized Statement and should not introduce additional normative obligations.

Incoming Traceability should use the wiki Backlinks function rather than a manually maintained list.

To reference this requirement Statement from another wiki page, insert:

{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-005#Statement&noheader&nofooter&noeditbtn}}

Do not rename this page after an external citation unless a redirect or move plan is in place.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-c-requirements/03-functional-requirements/03-05-air-gap-operations/fr-ag-005.1784392429.txt.gz
  • Last modified: 2026/07/18 09:33
  • by nick_dido