dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:start

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:start [2026/07/30 13:24] – removed - external edit (Unknown date) 127.0.0.1dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:start [2026/07/30 13:34] (current) nick_dido
Line 1: Line 1:
 +====== FR-COMP-010 — Transferable Compliance Findings ======
  
 +[[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:start|Go to Crucible Compliance Management Requirements]]
 +
 +===== Original Requirement =====
 +
 +> //The system shall capture compliance findings into the transferable dependency/evidence bundle (see §4.10) so findings from connected build accompany artifacts into disconnected enclave.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
 +
 +===== Assessment of Original Requirement =====
 +
 +The Original Requirement contains two distinct obligations:
 +
 +  - Inclusion of Compliance Findings in the transferable dependency/evidence bundle
 +  - Preservation of the relationship between the Compliance Findings and the Artifacts they describe when transferred from a [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environment]] to a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]]
 +
 +These obligations require separate verification and therefore should be represented by separate leaf requirements.
 +
 +The phrase **transferable dependency/evidence bundle** is normalized to the controlled term [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]].
 +
 +The phrase **connected build** does not identify a defined architectural object. The decomposition instead identifies the Connected Environment as the source environment.
 +
 +The phrase **disconnected enclave** is normalized to the controlled term Disconnected Environment unless the architecture establishes **Enclave** as a distinct controlled concept.
 +
 +The decomposition does not require Crucible to generate Compliance Findings, resolve Compliance Findings, or determine whether a transferred Artifact complies with a Compliance Baseline.
 +
 +===== Contents =====
 +
 +{{indexmenu>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010#1|js navbar nocookie maxjs#1 id#fr_comp_010_nav}}
 +
 +===== Requirement Status =====
 +
 +<todo>Review and approve the decomposition of FR-COMP-010.</todo>
 +
 +<todo>Create and approve FR-COMP-010a.</todo>
 +
 +<todo>Create and approve FR-COMP-010b.</todo>
 +
 +----
 +===== Issues =====
 +
 +<todo>Determine whether Compliance Finding requires a controlled definition in the shared Terms and Definitions corpus.</todo>
 +
 +<todo>Confirm that Transfer Bundle is the controlling term for the source phrase transferable dependency/evidence bundle.</todo>
 +
 +<todo>Determine whether the source term disconnected enclave means Disconnected Environment or requires a distinct Enclave definition.</todo>
 +
 +<todo>Determine whether separate requirements govern verification of Compliance Findings and their Artifact associations after Transfer Bundle import.</todo>
 +
 +----
 +===== Notes for Editors =====
 +
 +This page is a non-leaf requirement page and therefore retains a trailing '':start'' in its namespace.
 +
 +The namespace for this requirement is:
 +
 +''dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-06-compliance-management:fr-comp-010:start''
 +
 +The child requirements are leaf pages nested beneath the FR-COMP-010 namespace and omit a trailing '':start''.
 +
 +Use the following controlling Terms and Definitions entries:
 +
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle|Transfer Bundle]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifact]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environment]]
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]]
 +
 +The decomposition separates inclusion of Compliance Findings in a Transfer Bundle from preservation of the relationship between each Compliance Finding and the Artifact it describes.
 +
 +FR-COMP-010 does not require Crucible to:
 +
 +  * Generate the Compliance Findings
 +  * Determine the validity of the Compliance Findings
 +  * Resolve the Compliance Findings
 +  * Remediate the affected Artifacts
 +  * Reassess the affected Artifacts
 +  * Determine whether the affected Artifacts comply with a Compliance Baseline
 +
 +Do not add finding generation, validation, resolution, remediation, reassessment, or compliance-decision responsibilities unless the controlling requirement changes through an approved requirements process.
 +
 +----
 +
 +<WRAP centeralign>
 +© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.
 +</WRAP>