Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision | |||
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-004:start [2026/08/01 06:19] – removed - external edit (Unknown date) 127.0.0.1 | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-004:start [2026/08/01 06:19] (current) – ↷ Page moved and renamed from dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-004 to dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== FR-COMP-004 — Compliance Evidence Artifacts ====== | ||
| + | [[dido: | ||
| + | |||
| + | ===== Statement ===== | ||
| + | |||
| + | [[dido: | ||
| + | |||
| + | ===== Derived From ===== | ||
| + | |||
| + | This requirement derives from: | ||
| + | |||
| + | * Crucible System Requirements Specification, | ||
| + | |||
| + | The Original Requirement states: | ||
| + | |||
| + | > //The system shall generate compliance evidence artifacts.// | ||
| + | |||
| + | FR-COMP-004: | ||
| + | |||
| + | * Replaces **The system** with the defined system name [[dido: | ||
| + | * Changes **shall** to the established uppercase normative form **SHALL** | ||
| + | * Retains the direct and observable verb **generate** | ||
| + | * Links **Evidence** and **Artifacts** to their controlling definitions | ||
| + | * Capitalizes **Compliance Evidence Artifacts** as the named output | ||
| + | |||
| + | No other substantive normalization is required. | ||
| + | |||
| + | ===== Rationale ===== | ||
| + | |||
| + | Compliance Evidence Artifacts provide durable information produced by compliance activities. | ||
| + | |||
| + | A Compliance Evidence Artifact can document: | ||
| + | |||
| + | * The evaluated subject | ||
| + | * The applicable [[dido: | ||
| + | * The compliance criteria evaluated | ||
| + | * The evaluation method | ||
| + | * Compliance Findings | ||
| + | * Passed and failed evaluations | ||
| + | * Observed values | ||
| + | * Evaluation timestamps | ||
| + | * The Compliance Scanning Tool | ||
| + | * Supporting content digests | ||
| + | * References to related reports or records | ||
| + | |||
| + | Compliance Evidence Artifacts allow actors and processes to inspect, retain, transfer, and associate compliance results with the subjects those results describe. | ||
| + | |||
| + | This requirement establishes generation of Compliance Evidence Artifacts without prescribing: | ||
| + | |||
| + | * The minimum contents of each Artifact | ||
| + | * An Artifact format | ||
| + | * An Artifact schema | ||
| + | * Artifact signing | ||
| + | * Artifact verification | ||
| + | * Artifact approval | ||
| + | * Artifact retention | ||
| + | * Artifact transfer | ||
| + | * Artifact publication | ||
| + | * Inclusion in a [[dido: | ||
| + | * Use in an SCTM, RMF activity, or ATO process | ||
| + | |||
| + | Separate requirements, | ||
| + | |||
| + | ===== Applies To ===== | ||
| + | |||
| + | This requirement applies to: | ||
| + | |||
| + | * [[dido: | ||
| + | * Compliance activities | ||
| + | * Compliance [[dido: | ||
| + | * [[dido: | ||
| + | * Compliance Evidence Artifact generation operations | ||
| + | |||
| + | ===== Verification ===== | ||
| + | |||
| + | Verification confirms that: | ||
| + | |||
| + | - A compliance activity is selected for testing | ||
| + | - The tested compliance activity produces compliance results | ||
| + | - [[dido: | ||
| + | - The generated Artifact identifies or references the compliance activity or evaluated subject | ||
| + | - The resulting Compliance Evidence Artifact can be identified as the output of the tested generation operation | ||
| + | |||
| + | ===== Referenced By ===== | ||
| + | |||
| + | The following pages reference this requirement: | ||
| + | |||
| + | {{backlinks> | ||
| + | |||
| + | ===== Implementation Status ===== | ||
| + | |||
| + | Implemented and Verified | ||
| + | |||
| + | ===== Requirement Status ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Issues ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Notes for Editors ===== | ||
| + | |||
| + | This requirement page retains the stable requirement identifier '' | ||
| + | |||
| + | This page is a leaf requirement page and omits a trailing '': | ||
| + | |||
| + | The Statement preserves the approved source intent by requiring Crucible to generate Compliance Evidence Artifacts. | ||
| + | |||
| + | Do not add particular Artifact contents, formats, schemas, signatures, verification results, retention periods, transfer behavior, reporting behavior, or authorization-process uses unless the controlling requirement changes through an approved requirements process. | ||
| + | |||
| + | Do not merge Compliance Reports and Compliance Evidence Artifacts unless the controlling architecture defines them as the same Artifact type. | ||
| + | |||
| + | To reference this requirement Statement from another wiki page, insert: | ||
| + | |||
| + | <code dokuwiki> | ||
| + | {{section> | ||
| + | </ | ||
| + | |||
| + | ---- | ||
| + | |||
| + | <WRAP centeralign> | ||
| + | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. | ||
| + | </ | ||