FR-COMP-003 — Compliance Reporting
Statement
Crucible SHALL generate Compliance Reports.
Derived From
This requirement derives from:
-
Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-COMP-003
The Original Requirement states:
The system shall support compliance reporting.[C1]
FR-COMP-003:
-
Replaces The system with the defined system name Crucible
-
Changes shall to the established uppercase normative form SHALL
-
Replaces the weak phrase support compliance reporting with the observable behavior generate Compliance Reports
No other substantive normalization is required.
Rationale
A Compliance Report communicates the results of compliance activities in a form that an actor or process can review, distribute, retain, or use as input to another activity.
A Compliance Report can include:
-
The evaluated subject
-
The applicable Compliance Baseline
-
The compliance criteria evaluated
-
Compliance Findings
-
Passed and failed evaluations
-
Severity classifications
-
Evaluation timestamps
-
Scanning-tool information
-
References to supporting Evidence
-
Remediation information
-
Summary results
This requirement establishes generation of Compliance Reports without prescribing:
-
A report format
-
A report schema
-
A presentation layout
-
A delivery mechanism
-
A report recipient
-
Report publication
-
Report retention
-
Report approval
-
Remediation behavior
-
Generation of separate Compliance Evidence Artifacts
Separate requirements, architecture specifications, workflows, or reporting profiles define those subjects and behaviors.
Applies To
This requirement applies to:
-
Compliance Reports
-
Compliance Findings
-
Compliance reporting operations
Verification
Verification confirms that:
-
Compliance results are selected for reporting
-
Crucible generates a Compliance Report from the selected compliance results
-
The generated Compliance Report identifies the evaluated subject
-
The generated Compliance Report communicates the selected compliance results
-
The resulting Compliance Report can be identified as the output of the tested reporting operation
Referenced By
The following pages reference this requirement:
Implementation Status
Implemented and Verified
Requirement Status
Review and approve FR-COMP-003 as a leaf requirement.
Issues
Determine whether Compliance Report requires a controlled definition in the shared Terms and Definitions corpus.
Determine whether separate requirements define the minimum required contents of a Compliance Report.
Determine whether separate requirements govern Compliance Report formats, retention, publication, and distribution.
Notes for Editors
This requirement page retains the stable requirement identifier FR-COMP-003.
This page is a leaf requirement page and omits a trailing :start from its namespace.
The Statement preserves the approved source intent by requiring Crucible to generate Compliance Reports.
Do not change generate to display, publish, export, distribute, or retain unless the controlling requirement identifies that behavior.
Do not add a report format, schema, layout, recipient, delivery mechanism, retention period, approval process, or Evidence-generation obligation unless the controlling requirement changes through an approved requirements process.
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-003#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.