Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision | |||
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-007:start [2026/08/01 06:20] – removed - external edit (Unknown date) 127.0.0.1 | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-007:start [2026/08/01 06:20] (current) – ↷ Page moved and renamed from dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-007 to dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== FR-COMP-007 — Custom Compliance Frameworks ====== | ||
| + | [[dido: | ||
| + | |||
| + | ===== Statement ===== | ||
| + | |||
| + | [[dido: | ||
| + | |||
| + | ===== Derived From ===== | ||
| + | |||
| + | This requirement derives from: | ||
| + | |||
| + | * Crucible System Requirements Specification, | ||
| + | |||
| + | The Original Requirement states: | ||
| + | |||
| + | > //The system shall support custom compliance frameworks.// | ||
| + | |||
| + | FR-COMP-007: | ||
| + | |||
| + | * Replaces **The system** with the defined system name [[dido: | ||
| + | * Changes **shall** to the established uppercase normative form **SHALL** | ||
| + | * Replaces the weak verb **support** with the observable behavior **define** | ||
| + | * Replaces the relative adjective **custom** with **user-defined** | ||
| + | * Preserves Compliance Framework as the source-identified subject | ||
| + | |||
| + | No other substantive normalization is required. | ||
| + | |||
| + | ===== Rationale ===== | ||
| + | |||
| + | Organizations can operate under compliance obligations that extend beyond standardized frameworks such as [[dido: | ||
| + | |||
| + | User-defined Compliance Frameworks allow an organization to represent compliance criteria derived from: | ||
| + | |||
| + | * Organizational policies | ||
| + | * Contractual obligations | ||
| + | * Program-specific requirements | ||
| + | * Mission-specific requirements | ||
| + | * Customer requirements | ||
| + | * Industry standards | ||
| + | * Regulatory obligations | ||
| + | * Local security policies | ||
| + | * Combinations of existing compliance frameworks | ||
| + | |||
| + | A user-defined Compliance Framework can organize: | ||
| + | |||
| + | * Compliance requirements | ||
| + | * Security controls | ||
| + | * Compliance criteria | ||
| + | * Control mappings | ||
| + | * Evaluation procedures | ||
| + | * Expected values | ||
| + | * Severity classifications | ||
| + | * Required Evidence | ||
| + | * References to source authorities | ||
| + | * Associated [[dido: | ||
| + | |||
| + | This requirement establishes definition of user-defined Compliance Frameworks without prescribing: | ||
| + | |||
| + | * A particular Compliance Framework | ||
| + | * A particular source authority | ||
| + | * Import of an externally defined framework | ||
| + | * Mapping between Compliance Frameworks | ||
| + | * Application of a Compliance Framework | ||
| + | * Compliance scanning | ||
| + | * Compliance assessment | ||
| + | * Compliance reporting | ||
| + | * Evidence generation | ||
| + | * Framework approval | ||
| + | * Framework publication | ||
| + | * Framework version management | ||
| + | |||
| + | Separate requirements, | ||
| + | |||
| + | ===== Applies To ===== | ||
| + | |||
| + | This requirement applies to: | ||
| + | |||
| + | * [[dido: | ||
| + | * User-defined Compliance Frameworks | ||
| + | * Compliance Framework definition operations | ||
| + | |||
| + | ===== Verification ===== | ||
| + | |||
| + | Verification confirms that: | ||
| + | |||
| + | - A set of user-specified compliance criteria is selected for testing | ||
| + | - [[dido: | ||
| + | - The resulting Compliance Framework can be identified | ||
| + | - The compliance criteria contained in the resulting Compliance Framework can be determined | ||
| + | - The resulting Compliance Framework is not restricted to a predefined DISA STIG or FedRAMP framework | ||
| + | |||
| + | ===== Referenced By ===== | ||
| + | |||
| + | The following pages reference this requirement: | ||
| + | |||
| + | {{backlinks> | ||
| + | |||
| + | ===== Implementation Status ===== | ||
| + | |||
| + | Implemented and Verified | ||
| + | |||
| + | ===== Requirement Status ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Issues ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Notes for Editors ===== | ||
| + | |||
| + | This requirement page retains the stable requirement identifier '' | ||
| + | |||
| + | This page is a leaf requirement page and omits a trailing '': | ||
| + | |||
| + | The Statement preserves the approved source intent by requiring Crucible to define user-defined Compliance Frameworks. | ||
| + | |||
| + | The Statement uses **user-defined** rather than **custom** because **custom** does not identify who establishes the framework or how the framework differs from a predefined framework. | ||
| + | |||
| + | Do not change **define** to **provide**, | ||
| + | |||
| + | Do not add framework mapping, approval, publication, | ||
| + | |||
| + | To reference this requirement Statement from another wiki page, insert: | ||
| + | |||
| + | <code dokuwiki> | ||
| + | {{section> | ||
| + | </ | ||
| + | |||
| + | ---- | ||
| + | |||
| + | <WRAP centeralign> | ||
| + | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. | ||
| + | </ | ||