Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-009:start [2026/07/30 13:12] – removed - external edit (Unknown date) 127.0.0.1 | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-009:start [2026/07/30 13:20] (current) – nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== FR-COMP-009 — Security-Control Implementation Evidence ====== | ||
| + | [[dido: | ||
| + | |||
| + | ===== Original Requirement ===== | ||
| + | |||
| + | > //The system shall generate security-control implementation evidence suitable for supporting [[dido: | ||
| + | |||
| + | ===== Assessment of Original Requirement ===== | ||
| + | |||
| + | The Original Requirement identifies three distinct uses for Security-Control Implementation [[dido: | ||
| + | |||
| + | - Inclusion in a [[dido: | ||
| + | - Use in [[dido: | ||
| + | - Use in [[dido: | ||
| + | |||
| + | Each use has a distinct purpose and requires separate verification. The Original Requirement should therefore be decomposed into three leaf requirements. | ||
| + | |||
| + | Generation of Security-Control Implementation Evidence is the common behavior across the three leaf requirements. It does not require a separate leaf because the Original Requirement does not establish an independent Evidence-generation obligation outside the SCTM, RMF, and ATO contexts. | ||
| + | |||
| + | The phrase **suitable for supporting** does not identify an observable behavior or the characteristics that make the Evidence suitable. Each child Statement therefore identifies the intended use directly. | ||
| + | |||
| + | The decomposition does not assign security-control approval, risk-management, | ||
| + | |||
| + | ===== Contents ===== | ||
| + | |||
| + | {{indexmenu> | ||
| + | |||
| + | ===== Requirement Status ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Issues ===== | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | < | ||
| + | |||
| + | ---- | ||
| + | ===== Notes for Editors ===== | ||
| + | |||
| + | This page is a non-leaf requirement page and therefore retains a trailing '': | ||
| + | |||
| + | The namespace for this requirement is: | ||
| + | |||
| + | '' | ||
| + | |||
| + | The child requirements are leaf pages nested beneath the FR-COMP-009 namespace and omit a trailing '': | ||
| + | |||
| + | Use the following controlling Terms and Definitions entries: | ||
| + | |||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | |||
| + | The decomposition contains three leaf requirements because the Original Requirement identifies three uses of Security-Control Implementation Evidence. | ||
| + | |||
| + | Do not create a separate generic Evidence-generation leaf unless the controlling source adds an independent requirement to generate Security-Control Implementation Evidence outside the SCTM, RMF, and ATO contexts. | ||
| + | |||
| + | FR-COMP-009 does not require Crucible to: | ||
| + | |||
| + | * Approve a Security Control implementation | ||
| + | * Perform the responsibilities of a control assessor | ||
| + | * Make a risk-management decision | ||
| + | * Accept residual risk | ||
| + | * Issue an Authorization to Operate | ||
| + | * Act as an [[dido: | ||
| + | |||
| + | Do not add Security Control approval, assessment authority, risk acceptance, authorization, | ||
| + | |||
| + | ---- | ||
| + | |||
| + | <WRAP centeralign> | ||
| + | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. | ||
| + | </ | ||