FR-COMP-004 — Compliance Evidence Artifacts
Statement
Derived From
This requirement derives from:
-
Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-COMP-004
The Original Requirement states:
The system shall generate compliance evidence artifacts.[C1]
FR-COMP-004:
-
Replaces The system with the defined system name Crucible
-
Changes shall to the established uppercase normative form SHALL
-
Retains the direct and observable verb generate
-
Links Evidence and Artifacts to their controlling definitions
-
Capitalizes Compliance Evidence Artifacts as the named output
No other substantive normalization is required.
Rationale
Compliance Evidence Artifacts provide durable information produced by compliance activities.
A Compliance Evidence Artifact can document:
-
The evaluated subject
-
The applicable Compliance Baseline
-
The compliance criteria evaluated
-
The evaluation method
-
Compliance Findings
-
Passed and failed evaluations
-
Observed values
-
Evaluation timestamps
-
The Compliance Scanning Tool
-
Supporting content digests
-
References to related reports or records
Compliance Evidence Artifacts allow actors and processes to inspect, retain, transfer, and associate compliance results with the subjects those results describe.
This requirement establishes generation of Compliance Evidence Artifacts without prescribing:
-
The minimum contents of each Artifact
-
An Artifact format
-
An Artifact schema
-
Artifact signing
-
Artifact verification
-
Artifact approval
-
Artifact retention
-
Artifact transfer
-
Artifact publication
-
Inclusion in a Transfer Bundle
-
Use in an SCTM, RMF activity, or ATO process
Separate requirements, architecture specifications, workflows, or evidence profiles define those subjects and behaviors.
Applies To
This requirement applies to:
-
Compliance activities
-
Compliance Evidence
-
Compliance Evidence Artifact generation operations
Verification
Verification confirms that:
-
A compliance activity is selected for testing
-
The tested compliance activity produces compliance results
-
Crucible generates a Compliance Evidence Artifact from the compliance results
-
The generated Artifact identifies or references the compliance activity or evaluated subject
-
The resulting Compliance Evidence Artifact can be identified as the output of the tested generation operation
Referenced By
The following pages reference this requirement:
Implementation Status
Implemented and Verified
Requirement Status
Review and approve FR-COMP-004 as a leaf requirement.
Issues
Determine whether Compliance Evidence Artifact requires a controlled definition in the shared Terms and Definitions corpus.
Determine whether separate requirements define the minimum required contents and metadata of a Compliance Evidence Artifact.
Determine whether separate requirements govern signing, verification, retention, transfer, and publication of Compliance Evidence Artifacts.
Notes for Editors
This requirement page retains the stable requirement identifier FR-COMP-004.
This page is a leaf requirement page and omits a trailing :start from its namespace.
The Statement preserves the approved source intent by requiring Crucible to generate Compliance Evidence Artifacts.
Do not add particular Artifact contents, formats, schemas, signatures, verification results, retention periods, transfer behavior, reporting behavior, or authorization-process uses unless the controlling requirement changes through an approved requirements process.
Do not merge Compliance Reports and Compliance Evidence Artifacts unless the controlling architecture defines them as the same Artifact type.
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-004#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.