Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision | |||
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-003:start [2026/08/01 06:19] – removed - external edit (Unknown date) 127.0.0.1 | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-003:start [2026/08/01 06:19] (current) – ↷ Page moved and renamed from dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-003 to dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== FR-COMP-003 — Compliance Reporting ====== | ||
| + | [[dido: | ||
| + | |||
| + | ===== Statement ===== | ||
| + | |||
| + | [[dido: | ||
| + | |||
| + | ===== Derived From ===== | ||
| + | |||
| + | This requirement derives from: | ||
| + | |||
| + | * Crucible System Requirements Specification, | ||
| + | |||
| + | The Original Requirement states: | ||
| + | |||
| + | > //The system shall support compliance reporting.// | ||
| + | |||
| + | FR-COMP-003: | ||
| + | |||
| + | * Replaces **The system** with the defined system name [[dido: | ||
| + | * Changes **shall** to the established uppercase normative form **SHALL** | ||
| + | * Replaces the weak phrase **support compliance reporting** with the observable behavior **generate Compliance Reports** | ||
| + | |||
| + | No other substantive normalization is required. | ||
| + | |||
| + | ===== Rationale ===== | ||
| + | |||
| + | A Compliance Report communicates the results of compliance activities in a form that an actor or process can review, distribute, retain, or use as input to another activity. | ||
| + | |||
| + | A Compliance Report can include: | ||
| + | |||
| + | * The evaluated subject | ||
| + | * The applicable [[dido: | ||
| + | * The compliance criteria evaluated | ||
| + | * Compliance Findings | ||
| + | * Passed and failed evaluations | ||
| + | * Severity classifications | ||
| + | * Evaluation timestamps | ||
| + | * Scanning-tool information | ||
| + | * References to supporting [[dido: | ||
| + | * Remediation information | ||
| + | * Summary results | ||
| + | |||
| + | This requirement establishes generation of Compliance Reports without prescribing: | ||
| + | |||
| + | * A report format | ||
| + | * A report schema | ||
| + | * A presentation layout | ||
| + | * A delivery mechanism | ||
| + | * A report recipient | ||
| + | * Report publication | ||
| + | * Report retention | ||
| + | * Report approval | ||
| + | * Remediation behavior | ||
| + | * Generation of separate Compliance Evidence Artifacts | ||
| + | |||
| + | Separate requirements, | ||
| + | |||
| + | ===== Applies To ===== | ||
| + | |||
| + | This requirement applies to: | ||
| + | |||
| + | * [[dido: | ||
| + | * Compliance Reports | ||
| + | * Compliance Findings | ||
| + | * Compliance reporting operations | ||
| + | |||
| + | ===== Verification ===== | ||
| + | |||
| + | Verification confirms that: | ||
| + | |||
| + | - Compliance results are selected for reporting | ||
| + | - [[dido: | ||
| + | - The generated Compliance Report identifies the evaluated subject | ||
| + | - The generated Compliance Report communicates the selected compliance results | ||
| + | - The resulting Compliance Report can be identified as the output of the tested reporting operation | ||
| + | |||
| + | ===== Referenced By ===== | ||
| + | |||
| + | The following pages reference this requirement: | ||
| + | |||
| + | {{backlinks> | ||
| + | |||
| + | ===== Implementation Status ===== | ||
| + | |||
| + | Implemented and Verified | ||
| + | |||
| + | ===== Requirement Status ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Issues ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Notes for Editors ===== | ||
| + | |||
| + | This requirement page retains the stable requirement identifier '' | ||
| + | |||
| + | This page is a leaf requirement page and omits a trailing '': | ||
| + | |||
| + | The Statement preserves the approved source intent by requiring Crucible to generate Compliance Reports. | ||
| + | |||
| + | Do not change **generate** to **display**, | ||
| + | |||
| + | Do not add a report format, schema, layout, recipient, delivery mechanism, retention period, approval process, or Evidence-generation obligation unless the controlling requirement changes through an approved requirements process. | ||
| + | |||
| + | To reference this requirement Statement from another wiki page, insert: | ||
| + | |||
| + | <code dokuwiki> | ||
| + | {{section> | ||
| + | </ | ||
| + | |||
| + | ---- | ||
| + | |||
| + | <WRAP centeralign> | ||
| + | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. | ||
| + | </ | ||