This is an old revision of the document!


Annex D: Requirements Traceability

Go to Crucible

Annex D maps the canonical leaf requirements in Annex C: Requirements to the Crucible pages that reference them.

Annex C remains the canonical source for requirement titles, Statements, rationale, and verification information. Annex D provides traceability links and coverage information without restating or redefining the requirements.

The Requirements Traceability Index lists the canonical leaf requirements alphabetically by title.

The Requirement Title column links to the canonical requirement page. The Referenced By column identifies the Crucible pages that link to that requirement.

A requirement with no references requires review to determine whether:

  • The requirement lacks ConOps coverage
  • The requirement belongs outside the ConOps
  • The requirement represents a future capability
  • The requirement page or backlink is incomplete
  • The requirement requires an additional operational page
Requirement Title Referenced By
FR-COMP-009c — Authorization to Operate Evidence






FR-BAS-001 — Consume Baseline Repositories from a Workspace






FR-BAS-002 — Compose Selected Baselines






FR-BAS-003 — Process Predeployment and Postdeployment Steps






FR-BAS-004 — Perform Noninteractive Workspace Execution






OR-003a — Classified Environment Operations






FR-UI-002 — Command-Line Interface






FR-COMP-001 — Compliance Baseline Definitions






FR-COMP-004 — Compliance Evidence Artifacts






FR-COMP-010a — Compliance Finding Transfer Bundle Inclusion






FR-COMP-010b — Compliance Finding Association Preservation






FR-COMP-003 — Compliance Reporting






FR-COMP-008a — Compliance Scanning Abstraction






FR-COMP-002 — Compliance Scanning Tool Integration






FR-IMG-002 — Build Container Images






OR-003f — Cross-Domain Transfer Control






FR-COMP-007 — Custom Compliance Frameworks






FR-DEPC-001 — Capture Build Dependencies






FR-DEPC-002 — Preserve Dependencies in a Dependency Store






FR-DEPC-005 — Dependency Store Implementation Independence






FR-DEP-001 — Deploy Infrastructure Resources






FR-DEP-002 — Deploy Virtual Machines






FR-DEP-003 — Deploy Kubernetes Clusters






FR-DEP-004 — Deploy Containerized Workloads






FR-DEP-005 — Deploy Platform Services






FR-DEP-007 — Deployment Validation






FR-COMP-005 — DISA STIG Compliance Baselines






FR-MC-005 — Edge Deployments






FR-COMP-006 — FedRAMP Baseline Definitions






FR-MC-004 — Hybrid-Cloud Deployments






FR-IMG-006 — Image Promotion Workflows






FR-IMG-004 — Image Signing






FR-IMG-005 — Image Verification






FR-IMG-003 — Immutable Infrastructure Workflows






OR-003e — Information Handling Rule Enforcement






FR-COMP-008b — Multiple Operating-System Support






FR-DEPC-004 — Populate Offline Repositories






FR-MC-001 — Cloud Provider Abstraction






FR-MC-002 — Provider-Specific Extensions






FR-MC-003 — Deployment Portability Across Cloud Providers






FR-COMP-009b — Risk Management Framework Evidence






OR-003g — Security Domain Access Control






OR-003d — Security Domain Information Enforcement






OR-003c — Security Domain Resource Enforcement






FR-COMP-009a — Security Control Traceability Matrix Evidence






FR-UI-001 — Shared Interface Operations






FR-DEPC-003 — Produce a Transfer Bundle






OR-003b — Unclassified Environment Operations






FR-IMG-001 — Build Virtual Machine Images






FR-UI-003 — Web-Based User Interface






  • Each requirement title is displayed from the canonical requirement page
  • Do not add custom display text to requirement links
  • Confirm the canonical page title and namespace for each requirement
  • Add every remaining Annex C leaf requirement
  • Exclude true parent requirements that contain child requirements
  • Retain start for leaf requirements implemented as namespace index pages
  • Sort the completed table alphabetically by the displayed canonical page title
  • Treat a requirement with no returned backlinks as requiring coverage review

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • Confirm each displayed title against the canonical requirement page
  • Add every remaining Annex C leaf requirement
  • Exclude parent requirements that contain child requirements
  • Retain start for leaf requirements implemented as namespace index pages
  • Sort the final table alphabetically by canonical displayed title
  • A requirement with no returned backlinks requires coverage review

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

The traceability information follows these rules:

  • Include only canonical leaf requirements
  • Treat a requirement implemented as a namespace start page as a leaf when it has no child requirements
  • Exclude parent requirements that have leaf children
  • Link each requirement title to its canonical Annex C page
  • Sort the Requirements Traceability Index alphabetically by displayed title
  • Identify every Crucible page that directly references the requirement
  • Do not copy or paraphrase the canonical requirement Statement
  • Record requirements without references as uncovered until reviewed
  • Record ConOps pages without supporting requirements as unsupported until reviewed

Detailed traceability pages can use the following coverage statuses:

Status Meaning
Complete The referenced Crucible content provides operational coverage consistent with the requirement Statement
Partial The referenced content addresses only part of the requirement Statement
Not Covered No current Crucible page provides identifiable coverage
Outside ConOps Scope The requirement applies to another specification, design, implementation, verification, or governance artifact
Future Capability The requirement applies to a capability outside the current operational baseline
Review Required The available requirement or coverage information is insufficient to determine the appropriate status

Annex E: Issues records problems discovered during traceability review.

Examples include:

  • A requirement without operational coverage
  • A ConOps capability without a supporting requirement
  • A requirement that requires further decomposition
  • An ambiguous or incomplete requirement Statement
  • An incorrect parent or leaf classification
  • A missing requirement page
  • An inconsistent requirement namespace or title
  • A proposed future capability

Annex D records the traceability condition. Annex E records the issue and its resolution status.

Populate the Requirements Traceability Index only after confirming the complete Annex C leaf-requirement inventory.

Do not list true parent requirements when their leaf children provide the normative Statements.

Where a leaf requirement uses a namespace start page for numerical ordering, link to the actual start page.

The Referenced By column should derive from direct links to the canonical requirement page wherever the available DokuWiki backlink mechanism permits dynamic generation.


© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/02-crusible/99-annexes/annex-d-requirements-traceability/start.1785616747.txt.gz
  • Last modified: 2026/08/01 13:39
  • by nick_dido