Annex D: Requirements Traceability

Go to Crucible

Annex D maps the canonical leaf requirements in Annex C: Requirements to the Crucible pages that reference them.

Annex C remains the canonical source for requirement titles, Statements, rationale, and verification information. Annex D provides traceability links and coverage information without restating or redefining the requirements.

The Requirements Traceability Index lists the canonical leaf requirements alphabetically by title.

The Requirement Title column links to the canonical requirement page. The Referenced By column identifies the Crucible pages that link to that requirement.

A requirement with no references requires review to determine whether:

  • The requirement lacks ConOps coverage
  • The requirement belongs outside the ConOps
  • The requirement represents a future capability
  • The requirement page or backlink is incomplete
  • The requirement requires an additional operational page
Requirement Title Referenced By
MO-005f — Approved Infrastructure Baseline Preservation
MO-005d — Approved Infrastructure Baseline Selection
FR-AG-002 — Artifact Export Packages
FR-AG-003 — Artifact Import Packages
FR-COMP-009c — Authorization to Operate Evidence
MO-004c — Authorized Resource Use
FR-DSO-004 — Automated Build Execution
FR-DSO-005 — Automated Deployment Execution
FR-DSO-006 — Automated Validation Execution
FR-AG-004 — Baseline Synchronization
FR-IMG-002 — Build Container Images
FR-IMG-001 — Build Virtual Machine Images
FR-DEPC-001 — Capture Build Dependencies
FR-DSO-003 — CI/CD Pipeline Integration
OR-003a — Classified Environment Operations
FR-MC-001 — Cloud Provider Abstraction
FR-UI-002 — Command-Line Interface
MO-001e — Compliance Baseline Conformance
FR-COMP-001 — Compliance Baseline Definitions
FR-COMP-004 — Compliance Evidence Artifacts
FR-COMP-010b — Compliance Finding Association Preservation
FR-COMP-010a — Compliance Finding Transfer Bundle Inclusion
OR-001f — Compliance Officer Operations
FR-COMP-003 — Compliance Reporting
FR-COMP-008a — Compliance Scanning Abstraction
FR-COMP-002 — Compliance Scanning Tool Integration
FR-BAS-002 — Compose Selected Baselines
OR-004a — Concurrent Environment Deployment
OR-004b — Concurrent Environment Management
FR-CFG-005 — Configuration Version History
MO-004a — Connected Environment Operations
FR-BAS-001 — Consume Baseline Repositories from a Workspace
OR-003f — Cross-Domain Transfer Control
MO-003a — Cross-Platform Deployment
FR-COMP-007 — Custom Compliance Frameworks
FR-CFG-001 — Declarative Infrastructure Configuration
FR-DEPC-005 — Dependency Store Implementation Independence
FR-DEP-004 — Deploy Containerized Workloads
FR-DEP-001 — Deploy Infrastructure Resources
FR-DEP-003 — Deploy Kubernetes Clusters
FR-DEP-005 — Deploy Platform Services
FR-DEP-002 — Deploy Virtual Machines
OR-002b — Deployment Acceptance Assessment
OR-002c — Deployment Acceptance Record
MO-001b — Deployment Duration
FR-MC-003 — Deployment Portability Across Cloud Providers
FR-DEP-006 — Deployment Rollback
OR-002a — Deployment to a Supported Target
FR-AG-005 — Deployment Traceability Across Disconnected Environments
FR-DEP-007 — Deployment Validation
OR-001a — Developer Operations
OR-001b — DevSecOps Engineer Operations
FR-COMP-005 — DISA STIG Compliance Baselines
FR-AG-001 — Disconnected Deployment Operations
MO-004b — Disconnected Environment Operations
MO-004d — Disconnected Resource Availability
or-005
FR-MC-005 — Edge Deployments
FR-CFG-004 — Environment Inheritance
FR-COMP-006 — FedRAMP Baseline Definitions
FR-DSO-001 — Git-Based Workflow Integration
FR-DSO-002 — GitOps Workflow Integration
FR-MC-004 — Hybrid-Cloud Deployments
FR-IMG-006 — Image Promotion Workflows
FR-IMG-004 — Image Signing
FR-IMG-005 — Image Verification
FR-IMG-003 — Immutable Infrastructure Workflows
OR-003e — Information Handling Rule Enforcement
FR-CFG-002 — Infrastructure as Code
MO-005a — Infrastructure Baseline Artifact Management
MO-005b — Infrastructure Baseline Identification
MO-005e — Infrastructure Baseline Reuse
MO-005c — Infrastructure Baseline Revision Control
MO-005g — Infrastructure Deployment Baseline Traceability
MO-001a — Infrastructure Environment Creation
MO-006e — Infrastructure Environment Retirement
MO-006b — Infrastructure Lifecycle Initiation
MO-006c — Infrastructure Lifecycle State Recording
MO-006d — Infrastructure Lifecycle Transition Execution
MO-003d — Limitation of Provider-Specific Dependencies
MO-002a — Maximum Platform Deployment Duration
FR-COMP-008b — Multiple Operating-System Support
MO-006a — Operational Lifecycle Association
FR-BAS-004 — Perform Noninteractive Workspace Execution
MO-002b — Platform Deployment Duration Reduction
OR-001c — Platform Engineer Operations
FR-DEPC-004 — Populate Offline Repositories
FR-DEPC-002 — Preserve Dependencies in a Dependency Store
FR-BAS-003 — Process Predeployment and Postdeployment Steps
FR-DEPC-003 — Produce a Transfer Bundle
MO-003b — Provider-Independent Crucible Description
MO-003c — Provider-Independent Infrastructure Baseline
FR-MC-002 — Provider-Specific Extensions
MO-001c — Reproducibility
FR-CFG-003 — Reusable Infrastructure Blueprints
FR-COMP-009b — Risk Management Framework Evidence
MO-001d — Security Baseline Conformance
FR-COMP-009a — Security Control Traceability Matrix Evidence
OR-003g — Security Domain Access Control
OR-003d — Security Domain Information Enforcement
OR-003c — Security Domain Resource Enforcement
OR-001e — Security Engineer Operations
FR-UI-001 — Shared Interface Operations
OR-001d — System Administrator Operations
OR-003b — Unclassified Environment Operations
FR-UI-003 — Web-Based User Interface
  • Each requirement title is displayed from the canonical requirement page
  • Do not add custom display text to requirement links
  • Confirm the canonical page title and namespace for each requirement
  • Add every remaining Annex C leaf requirement
  • Exclude true parent requirements that contain child requirements
  • Retain start for leaf requirements implemented as namespace index pages
  • Sort the completed table alphabetically by the displayed canonical page title
  • Treat a requirement with no returned backlinks as requiring coverage review

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • Confirm each displayed title against the canonical requirement page
  • Add every remaining Annex C leaf requirement
  • Exclude parent requirements that contain child requirements
  • Retain start for leaf requirements implemented as namespace index pages
  • Sort the final table alphabetically by canonical displayed title
  • A requirement with no returned backlinks requires coverage review

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

The traceability information follows these rules:

  • Include only canonical leaf requirements
  • Treat a requirement implemented as a namespace start page as a leaf when it has no child requirements
  • Exclude parent requirements that have leaf children
  • Link each requirement title to its canonical Annex C page
  • Sort the Requirements Traceability Index alphabetically by displayed title
  • Identify every Crucible page that directly references the requirement
  • Do not copy or paraphrase the canonical requirement Statement
  • Record requirements without references as uncovered until reviewed
  • Record ConOps pages without supporting requirements as unsupported until reviewed

Detailed traceability pages can use the following coverage statuses:

Status Meaning
Complete The referenced Crucible content provides operational coverage consistent with the requirement Statement
Partial The referenced content addresses only part of the requirement Statement
Not Covered No current Crucible page provides identifiable coverage
Outside ConOps Scope The requirement applies to another specification, design, implementation, verification, or governance artifact
Future Capability The requirement applies to a capability outside the current operational baseline
Review Required The available requirement or coverage information is insufficient to determine the appropriate status

Annex E: Issues records problems discovered during traceability review.

Examples include:

  • A requirement without operational coverage
  • A ConOps capability without a supporting requirement
  • A requirement that requires further decomposition
  • An ambiguous or incomplete requirement Statement
  • An incorrect parent or leaf classification
  • A missing requirement page
  • An inconsistent requirement namespace or title
  • A proposed future capability

Annex D records the traceability condition. Annex E records the issue and its resolution status.

Populate the Requirements Traceability Index only after confirming the complete Annex C leaf-requirement inventory.

Do not list true parent requirements when their leaf children provide the normative Statements.

Where a leaf requirement uses a namespace start page for numerical ordering, link to the actual start page.

The Referenced By column should derive from direct links to the canonical requirement page wherever the available DokuWiki backlink mechanism permits dynamic generation.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-d-requirements-traceability/start.txt
  • Last modified: 2026/08/02 00:18
  • by nick_dido