FR-COMP-006 — FedRAMP Baseline Definitions
Statement
Crucible SHALL define Federal Risk and Authorization Management Program (FedRAMP) Compliance Baselines.
Derived From
This requirement derives from:
-
Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-COMP-006
The Original Requirement states:
FR-COMP-006:
-
Replaces The system with the defined system name Crucible
-
Changes shall to the established uppercase normative form SHALL
-
Replaces the weak phrase support FedRAMP baseline definitions with the observable behavior define FedRAMP Compliance Baselines
-
Links FedRAMP and Compliance Baselines to their controlling definitions
-
Preserves FedRAMP as the source-identified compliance framework
No other substantive normalization is required.
Rationale
The Federal Risk and Authorization Management Program (FedRAMP) establishes standardized security requirements and assessment expectations for cloud services used by United States federal agencies.
A FedRAMP Compliance Baseline enables Crucible compliance activities to represent criteria derived from an identified FedRAMP baseline.
Such a Compliance Baseline can include:
-
Security controls
-
Control enhancements
-
Control parameters
-
Assessment objectives
-
Required implementation information
-
Applicability conditions
-
Required Evidence
-
References to the source FedRAMP baseline
-
References to related control catalogs
This requirement establishes definition of FedRAMP Compliance Baselines without prescribing:
-
A particular FedRAMP baseline
-
A particular FedRAMP revision
-
Import of externally defined FedRAMP content
-
Application of a Compliance Baseline
-
Compliance scanning
-
Compliance assessment
-
Remediation
-
Compliance reporting
-
Evidence generation
-
Automatic updates
-
Approval or lifecycle management
Separate requirements, architecture specifications, workflows, or policies define those subjects and behaviors.
Applies To
This requirement applies to:
-
FedRAMP Compliance Baselines
-
FedRAMP Compliance Baseline definition operations
Verification
Verification confirms that:
-
A FedRAMP baseline is selected for testing
-
Crucible defines a Compliance Baseline associated with the selected FedRAMP baseline
-
The defined Compliance Baseline identifies the FedRAMP baseline from which it derives
-
The compliance criteria represented by the defined Compliance Baseline can be determined
-
The resulting Compliance Baseline can be identified
Referenced By
The following pages reference this requirement:
Implementation Status
Implemented and Verified
Requirement Status
Review and approve FR-COMP-006 as a leaf requirement.
Issues
Determine whether separate requirements identify the FedRAMP baselines and revisions that Crucible must define.
Determine whether separate requirements govern importing, updating, approving, maintaining, and applying FedRAMP Compliance Baselines.
Notes for Editors
This requirement page retains the stable requirement identifier FR-COMP-006.
This page is a leaf requirement page and omits a trailing :start from its namespace.
The Statement preserves the approved source intent by requiring Crucible to define FedRAMP Compliance Baselines.
Use the following controlling Terms and Definitions entries:
Do not change define to provide, import, maintain, apply, scan against, or assess against unless the controlling requirement identifies that specific behavior.
Do not add a particular FedRAMP baseline, FedRAMP revision, cloud service, scanning tool, update mechanism, remediation process, reporting obligation, or Evidence-generation obligation unless the controlling requirement changes through an approved requirements process.
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-006#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.