FR-COMP-010b — Compliance Finding Association Preservation
Statement
Crucible SHALL preserve the association between each Compliance Finding and the Artifact to which the Compliance Finding applies when transferring them in a Transfer Bundle from a Connected Environment to a Disconnected Environment.
Derived From
This requirement derives from:
-
Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-COMP-010
The Original Requirement states:
The system shall capture compliance findings into the transferable dependency/evidence bundle (see §4.10) so findings from connected build accompany artifacts into disconnected enclave.[C1]
FR-COMP-010b:
-
Replaces The system with the defined system name Crucible
-
Changes shall to the established uppercase normative form SHALL
-
Extracts preservation of the association between Compliance Findings and affected Artifacts as an independently verifiable requirement
-
Replaces transferable dependency/evidence bundle with the controlled term Transfer Bundle
-
Replaces connected build with the controlled term Connected Environment
-
Replaces disconnected enclave with the controlled term Disconnected Environment
-
Assigns inclusion of Compliance Findings and affected Artifacts in the same Transfer Bundle to FR-COMP-010a
Rationale
A Compliance Finding remains useful after transfer only when its association with the evaluated Artifact remains identifiable.
Preserving this association enables actors and processes in a Disconnected Environment to determine which Compliance Findings apply to each transferred Artifact.
FR-COMP-010a governs inclusion of Compliance Findings and affected Artifacts in the same Transfer Bundle. This requirement governs preservation of the association between them.
This requirement does not require Crucible to:
-
Generate Compliance Findings
-
Validate Compliance Findings
-
Resolve Compliance Findings
-
Remediate affected Artifacts
-
Reassess affected Artifacts
-
Determine whether affected Artifacts comply with a Compliance Baseline
Applies To
This requirement applies to:
Verification
Verification confirms that:
-
An Artifact with one or more associated Compliance Findings is selected for testing
-
Crucible includes the selected Artifact and its associated Compliance Findings in a Transfer Bundle
-
Crucible transfers the Transfer Bundle from a Connected Environment to a Disconnected Environment
-
The transferred Artifact can be identified in the Disconnected Environment
-
Each transferred Compliance Finding can be identified in the Disconnected Environment
-
The association between each transferred Compliance Finding and the Artifact to which it applies can be determined in the Disconnected Environment
Referenced By
The following pages reference this requirement:
Implementation Status
Implemented and Verified
Requirement Status
Review and approve FR-COMP-010b as a leaf requirement.
Issues
Confirm the controlled definition of Compliance Finding in the shared Terms and Definitions corpus.
Determine whether separate requirements define the identifier or reference mechanism used to preserve the association between a Compliance Finding and an Artifact.
Determine whether separate requirements govern verification of the preserved association after Transfer Bundle import.
Notes for Editors
This requirement page retains the derived requirement identifier FR-COMP-010b.
This page is a leaf requirement page and omits a trailing :start from its namespace.
The Statement addresses only preservation of the association between each Compliance Finding and the Artifact to which the Compliance Finding applies during transfer between Connected and Disconnected Environments.
FR-COMP-010a governs inclusion of Compliance Findings and affected Artifacts in the same Transfer Bundle.
Use the following controlling Terms and Definitions entry for Compliance Finding:
Do not add finding generation, validation, resolution, remediation, reassessment, identifier-format, or compliance-decision obligations unless the controlling requirement changes through an approved requirements process.
To reference this requirement Statement from another wiki page, insert:
{{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:fr-comp-010b#Statement&noheader&nofooter&noeditbtn}}
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.