Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision | |||
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-008:fr-comp-008a [2026/07/30 07:37] – removed - external edit (Unknown date) 127.0.0.1 | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-008:fr-comp-008a [2026/07/30 07:37] (current) – ↷ Page moved from dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-008a to dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-008:f nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== FR-COMP-008a — Compliance Scanning Abstraction ====== | ||
| + | [[dido: | ||
| + | |||
| + | ===== Statement ===== | ||
| + | |||
| + | [[dido: | ||
| + | |||
| + | ===== Derived From ===== | ||
| + | |||
| + | This requirement derives from: | ||
| + | |||
| + | * [[dido: | ||
| + | * Crucible System Requirements Specification, | ||
| + | |||
| + | The Original Requirement states: | ||
| + | |||
| + | > //The system shall provide an operating-system-agnostic compliance scanning abstraction. Compliance scanning shall not be limited to a single operating system (the current OpenSCAP/ | ||
| + | |||
| + | FR-COMP-008a: | ||
| + | |||
| + | * Replaces **The system** with the defined system name [[dido: | ||
| + | * Changes **shall** to the established uppercase normative form **SHALL** | ||
| + | * Retains the direct behavior **provide** | ||
| + | * Extracts provision of the Compliance Scanning Abstraction as an independently verifiable requirement | ||
| + | * Assigns operating-system coverage to FR-COMP-008b | ||
| + | * Excludes the OpenSCAP and RHEL 9 implementation example from the normative Statement | ||
| + | |||
| + | ===== Rationale ===== | ||
| + | |||
| + | A Compliance Scanning Abstraction separates Crucible compliance scanning operations from a particular scanning tool or operating-system-specific implementation. | ||
| + | |||
| + | The abstraction allows Crucible to use different compliance scanning implementations through a common architectural boundary. | ||
| + | |||
| + | This requirement establishes provision of the abstraction without prescribing: | ||
| + | |||
| + | * A particular Compliance Scanning Tool | ||
| + | * A particular operating system | ||
| + | * A particular provider | ||
| + | * A plugin mechanism | ||
| + | * A provider discovery mechanism | ||
| + | * An application programming interface | ||
| + | * A command-line interface | ||
| + | * A data exchange format | ||
| + | * A common Compliance Finding format | ||
| + | * Dynamic provider loading | ||
| + | * Automatic operating-system detection | ||
| + | |||
| + | Separate requirements, | ||
| + | |||
| + | ===== Applies To ===== | ||
| + | |||
| + | This requirement applies to: | ||
| + | |||
| + | * [[dido: | ||
| + | * Compliance scanning operations | ||
| + | * Compliance scanning implementations | ||
| + | * Compliance Scanning Tools | ||
| + | |||
| + | ===== Verification ===== | ||
| + | |||
| + | Verification confirms that: | ||
| + | |||
| + | - A compliance scanning operation is selected for testing | ||
| + | - Two compliance scanning implementations are configured behind the Compliance Scanning Abstraction | ||
| + | - [[dido: | ||
| + | - The selected compliance scanning operation can use either configured implementation without changing the Crucible operation that invokes the abstraction | ||
| + | - Each configured implementation returns an observable scanning result through the abstraction | ||
| + | |||
| + | ===== Referenced By ===== | ||
| + | |||
| + | The following pages reference this requirement: | ||
| + | |||
| + | {{backlinks> | ||
| + | |||
| + | ===== Implementation Status ===== | ||
| + | |||
| + | Implemented and Verified | ||
| + | |||
| + | ===== Requirement Status ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Issues ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Notes for Editors ===== | ||
| + | |||
| + | This requirement page retains the derived requirement identifier '' | ||
| + | |||
| + | This page is a leaf requirement page and omits a trailing '': | ||
| + | |||
| + | The Statement addresses only provision of the Compliance Scanning Abstraction. | ||
| + | |||
| + | FR-COMP-008b governs compliance scanning across two or more operating systems. | ||
| + | |||
| + | The OpenSCAP and RHEL 9 reference in the Original Requirement describes one implementation of the abstraction and does not create a requirement to use either technology. | ||
| + | |||
| + | Do not add provider loading, provider discovery, plugin registration, | ||
| + | |||
| + | To reference this requirement Statement from another wiki page, insert: | ||
| + | |||
| + | <code dokuwiki> | ||
| + | {{section> | ||
| + | </ | ||
| + | |||
| + | ---- | ||
| + | |||
| + | <WRAP centeralign> | ||
| + | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. | ||
| + | </ | ||