| Next revision | Previous revision |
| dido:03-dido-te:99-annexes:annex-c-requirements:01-mission-objectives:mo-001 [2026/08/04 02:55] – created nick_dido | dido:03-dido-te:99-annexes:annex-c-requirements:01-mission-objectives:mo-001 [2026/08/05 01:36] (current) – [Delivery Phase] nick_dido |
|---|
| ===== Statement ===== | ===== Statement ===== |
| |
| DIDO-TE SHALL restrict each operation on a Test Environment according to the Governance Policies of the Test Environment's governing [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domain]]. | [[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] SHALL maintain each [[dido:99_annexes:annex-b-terms-and-definitions:t:test_environment|Test Environment]] as [[dido:99_annexes:annex-b-terms-and-definitions:g:governed|Governed]] throughout its [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]]. |
| |
| ===== Source ===== | ===== Source ===== |
| * ''REQ-0086 — Substrate as a governed object with a recorded lifecycle'' | * ''REQ-0086 — Substrate as a governed object with a recorded lifecycle'' |
| |
| The source requirements establish the governance hierarchy, governance roles, Governance Policies, authorization boundaries, tenancy boundaries, Domain ownership of Test Environments, and governance of supporting infrastructure. | The Original Requirements establish mission-level intent concerning: |
| |
| MO-001 expresses the common mission-level outcome. The detailed governance, authorization, isolation, environment ownership, and lifecycle obligations remain separate Operational, Functional, Security, Logging and Auditing, and Data Management Requirements. | * A governance hierarchy |
| | * Governing [[dido:99_annexes:annex-b-terms-and-definitions:a:authority|Authorities]] |
| | * Governance organizations |
| | * Governance [[dido:99_annexes:annex-b-terms-and-definitions:r:role|Roles]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_domain|Governance Domains]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_policy|Governance Policies]] |
| | * Membership decisions |
| | * Authorization boundaries |
| | * Tenancy boundaries |
| | * Test Environment governance |
| | * Supporting-infrastructure governance |
| | * Operational Lifecycle governance |
| | |
| | MO-001 expresses the common mission-level outcome that each Test Environment remains Governed throughout its Operational Lifecycle. |
| | |
| | The supporting Operational, Functional, Security, Logging and Auditing, and Data Management requirements define the independently verifiable obligations governing: |
| | |
| | * Governance structures |
| | * Authority |
| | * Role assignments |
| | * Governance Policy application |
| | * Authorization |
| | * Isolation |
| | * Test Environment ownership |
| | * Operational Lifecycle transitions |
| | * Governance records |
| | * Governance Evidence |
| |
| ===== Rationale ===== | ===== Rationale ===== |
| |
| A Test Environment can consume infrastructure, execute software, exchange information, create Evidence, access protected resources, and affect systems operated by multiple organizations. | A Test Environment can: |
| |
| DIDO-TE requires an explicit governance context for each Test Environment so that DIDO-TE can determine: | * Allocate and consume [[dido:99_annexes:annex-b-terms-and-definitions:r:resource|Resources]] |
| | * Use [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_resource|Operational Resources]] |
| | * Operate [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Nodes]] |
| | * Operate [[dido:99_annexes:annex-b-terms-and-definitions:n:node_set|Node Sets]] |
| | * Use [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_target|Deployment Targets]] |
| | * Perform [[dido:99_annexes:annex-b-terms-and-definitions:t:test_execution|Test Execution]] |
| | * Execute software |
| | * Exchange information |
| | * Access protected Resources |
| | * Create [[dido:99_annexes:annex-b-terms-and-definitions:t:test_result|Test Results]] |
| | * Create [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] |
| | * Affect systems operated by multiple [[dido:99_annexes:annex-b-terms-and-definitions:o:organization|Organizations]] |
| |
| * Which [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domain]] governs the Test Environment | Each Test Environment requires an explicit governance context that identifies: |
| * Which Governance Policies apply | |
| * Which principals may perform each operation | |
| * Which resources the Test Environment may use | |
| * Which information the Test Environment may access | |
| * Which operational boundaries apply | |
| * Which records DIDO-TE must preserve | |
| * Which approvals DIDO-TE requires | |
| * Which organization remains accountable for the Test Environment | |
| |
| Governance applies throughout the Test Environment lifecycle. Governance does not end after DIDO-TE creates or provisions the Test Environment. | * The governing Authority |
| | * The applicable Governance Domain |
| | * The governed Test Environment |
| | * The applicable scope |
| | * The applicable Organizations |
| | * The applicable [[dido:99_annexes:annex-b-terms-and-definitions:c:community_of_interest|Communities of Interest]] |
| | * The responsible [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actors]] |
| | * The applicable Roles |
| | * The applicable responsibilities |
| | * The applicable decision rights |
| | * The applicable Governance Policies |
| | * The applicable approval processes |
| | * The applicable change-control processes |
| | * The applicable exception and waiver processes |
| | * The applicable enforcement mechanisms |
| | * The applicable accountability mechanisms |
| | * The required Evidence |
| | * The required [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] |
| | * The required [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] |
| |
| The detailed requirements define the operations subject to governance and the mechanism for determining the applicable Governance Policies. MO-001 establishes the mission-level obligation to apply those policies consistently. | Governance applies throughout the Operational Lifecycle of the Test Environment. Governance does not end after DIDO-TE creates, provisions, deploys, or activates the Test Environment. |
| | |
| | The supporting requirements define how DIDO-TE establishes, applies, evaluates, records, and enforces the applicable governance context. MO-001 establishes the mission-level outcome that the Test Environment remains Governed. |
| |
| ===== Applies To ===== | ===== Applies To ===== |
| This requirement applies to: | This requirement applies to: |
| |
| * DIDO-TE | * [[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] |
| * Test Environments | * [[dido:99_annexes:annex-b-terms-and-definitions:t:test_environment|Test Environments]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:d:distributed_system|Distributed Systems]] | * [[dido:99_annexes:annex-b-terms-and-definitions:d:distributed_system|Distributed Systems]] |
| * Governing [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domains]] | * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_domain|Governance Domains]] |
| * Governance Policies | * Governing [[dido:99_annexes:annex-b-terms-and-definitions:a:authority|Authorities]] |
| * Governance roles | * [[dido:99_annexes:annex-b-terms-and-definitions:o:organization|Organizations]] |
| * Authorized principals | * [[dido:99_annexes:annex-b-terms-and-definitions:c:community_of_interest|Communities of Interest]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actors]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:r:role|Roles]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_policy|Governance Policies]] |
| * Test Environment operations | * Test Environment operations |
| * Test Environment resources | * Test Environment [[dido:99_annexes:annex-b-terms-and-definitions:r:resource|Resources]] |
| * Nodes | * [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_resource|Operational Resources]] |
| * Node Sets | * [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Nodes]] |
| * Deployment Targets | * [[dido:99_annexes:annex-b-terms-and-definitions:n:node_set|Node Sets]] |
| * Virtual Networks | * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_target|Deployment Targets]] |
| * Test Definitions | * [[dido:99_annexes:annex-b-terms-and-definitions:t:test_definition|Test Definitions]] |
| * Test Runs | * [[dido:99_annexes:annex-b-terms-and-definitions:t:test_run|Test Runs]] |
| * Test Results | * [[dido:99_annexes:annex-b-terms-and-definitions:t:test_result|Test Results]] |
| * Baseline Results | * [[dido:99_annexes:annex-b-terms-and-definitions:v:validation_decision|Validation Decisions]] |
| * Validation Decisions | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] | * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] | * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] | * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]] | * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]] |
| | * The [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] of each Test Environment |
| |
| ===== Verification ===== | ===== Verification ===== |
| Verification confirms that: | Verification confirms that: |
| |
| - Each Test Environment identifies exactly one governing [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domain]] | - Each Test Environment has an identified governance context |
| - DIDO-TE identifies the Governance Policies applicable to the Test Environment | - The governance context identifies the governing Authority |
| - DIDO-TE identifies the operations governed by each applicable Governance Policy | - The governance context identifies the applicable Governance Domain |
| - DIDO-TE identifies the principal requesting each Test Environment operation | - The governance context identifies the governed Test Environment |
| - DIDO-TE evaluates each requested operation against the applicable Governance Policies | - The governance context identifies its applicable scope |
| - DIDO-TE permits an operation when the applicable Governance Policies authorize the requesting principal to perform the operation | - The governance context identifies the applicable Organizations and Communities of Interest |
| - DIDO-TE refuses an operation when the applicable Governance Policies do not authorize the requesting principal to perform the operation | - The governance context identifies the applicable Actors and Roles |
| - DIDO-TE refuses an operation when the Test Environment does not identify a valid governing Domain | - The governance context identifies the applicable responsibilities and decision rights |
| - DIDO-TE prevents a principal governed by one tenancy boundary from operating a Test Environment governed by another tenancy boundary unless the applicable Governance Policies explicitly authorize the operation | - The governance context identifies the applicable Governance Policies |
| - DIDO-TE applies the Governance Policies throughout the Test Environment lifecycle | - The governance context identifies the applicable approval processes |
| - DIDO-TE records the governing Domain, requesting principal, requested operation, authorization result, operation result, and applicable Governance Policies | - The governance context identifies the applicable change-control processes |
| - The verification record preserves [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] among the Test Environment, governing Domain, applicable Governance Policies, requesting principal, requested operation, authorization result, operation result, and supporting [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] | - The governance context identifies the applicable exception and waiver processes |
| | - The governance context identifies the applicable enforcement mechanisms |
| | - The governance context identifies the applicable accountability and review processes |
| | - DIDO-TE applies the governance context to Test Environment operations |
| | - DIDO-TE evaluates each governed Test Environment operation according to the applicable Governance Policies |
| | - DIDO-TE applies the governance context throughout the Operational Lifecycle of the Test Environment |
| | - DIDO-TE applies the governance context in Connected, Disconnected, and Air-Gapped Environments |
| | - DIDO-TE preserves the Evidence required to demonstrate application of the governance context |
| | - DIDO-TE preserves Provenance for governance decisions and Test Environment operations |
| | - The verification record preserves Traceability among the Test Environment, governing Authority, Governance Domain, Actors, Roles, Governance Policies, governance decisions, Test Environment operations, Evidence, and verification result |
| |
| ===== Referenced By ===== | ===== Referenced By ===== |
| ===== Delivery Phase ===== | ===== Delivery Phase ===== |
| |
| Not Assessed | <todo>TBD</todo> |
| |
| ===== Implementation Status ===== | ===== Implementation Status ===== |
| |
| <todo>Assess the current DIDO-TE implementation against MO-001 and its supporting Operational, Functional, Security, Logging and Auditing, and Data Management Requirements.</todo> | <todo>Assess the current DIDO-TE implementation against MO-001 and its supporting Operational, Functional, Security, Logging and Auditing, and Data Management requirements.</todo> |
| |
| ===== Requirement Status ===== | ===== Requirement Status ===== |
| |
| <todo>Review and approve MO-001 as a proposed Mission Objective derived from the governance and Test Environment requirements in the draft DIDO-TE Requirements Register.</todo> | <todo>Review and approve MO-001 as a proposed Mission Objective consolidated from the governance and Test Environment requirements in the draft DIDO-TE Requirements Register.</todo> |
| |
| ---- | ---- |
| | |
| ===== Issues ===== | ===== Issues ===== |
| |
| The following unresolved issues affect this requirement: | The following unresolved issues affect this requirement: |
| |
| <todo>Define Test Environment in the shared DIDO Solutions Terms and Definitions corpus.</todo> | <todo>Define Governance in the shared DIDO Solutions Terms and Definitions corpus.</todo> |
| |
| <todo>Define Governance Policy in the shared DIDO Solutions Terms and Definitions corpus or identify the applicable controlling term.</todo> | <todo>Define the governance hierarchy applicable to DIDO-TE Test Environments.</todo> |
| | |
| | <todo>Define the relationship between a Test Environment and its governing Governance Domain.</todo> |
| | |
| | <todo>Define whether each Test Environment has one primary governing Governance Domain or can have multiple governing Governance Domains.</todo> |
| |
| <todo>Define the complete set of Test Environment operations governed by MO-001.</todo> | <todo>Define the complete set of Test Environment operations governed by MO-001.</todo> |
| |
| <todo>Define how DIDO-TE determines the governing Domain for a Test Environment.</todo> | <todo>Define how DIDO-TE identifies the governing Authority for a Test Environment.</todo> |
| |
| <todo>Define how DIDO-TE resolves Governance Policies inherited through the governance hierarchy.</todo> | <todo>Define how DIDO-TE resolves Governance Policies inherited through the governance hierarchy.</todo> |
| |
| <todo>Define the precedence and conflict-resolution rules for Governance Policies established at different levels of the governance hierarchy.</todo> | <todo>Define the precedence and conflict-resolution rules for Governance Policies established by different Authorities or at different levels of the governance hierarchy.</todo> |
| |
| <todo>Define the authorization decision required when an applicable Governance Policy is missing, invalid, unavailable, or internally inconsistent.</todo> | <todo>Define the decision required when an applicable Governance Policy is missing, invalid, unavailable, or internally inconsistent.</todo> |
| |
| <todo>Define the Evidence DIDO-TE preserves for each governance decision and Test Environment operation.</todo> | <todo>Define the Governance Evidence DIDO-TE preserves for each governance decision and Test Environment operation.</todo> |
| | |
| | <todo>Define the governance requirements applicable during each Test Environment Operational Lifecycle state and transition.</todo> |
| |
| ---- | ---- |
| | |
| ===== Notes for Editors ===== | ===== Notes for Editors ===== |
| |
| This requirement page should retain the stable requirement identifier ''MO-001''. | This requirement page retains the stable requirement identifier ''MO-001''. |
| |
| This page is a leaf requirement page and omits a trailing '':start'' from its namespace. | This page is a leaf requirement page and omits a trailing '':start'' from its namespace. |
| MO-001 consolidates mission-level intent from multiple Original Requirements. MO-001 does not result from splitting a single parent requirement and therefore uses a **Source** section rather than a **Derived From** section. | MO-001 consolidates mission-level intent from multiple Original Requirements. MO-001 does not result from splitting a single parent requirement and therefore uses a **Source** section rather than a **Derived From** section. |
| |
| Changes to the Statement should preserve: | Changes to the Statement preserve: |
| |
| * DIDO-TE as the responsible actor | * [[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] as the responsible Actor |
| * Each Test Environment operation as the governed activity | * Each [[dido:99_annexes:annex-b-terms-and-definitions:t:test_environment|Test Environment]] as the governed subject |
| * Governance Policies as the controlling rules | * [[dido:99_annexes:annex-b-terms-and-definitions:g:governed|Governed]] as the required condition |
| * The Test Environment's governing [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domain]] as the source of the applicable governance context | * The [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] as the temporal scope of the obligation |
| * Enforcement of the applicable Governance Policies as the required outcome | |
| |
| The supporting requirements should define: | The supporting requirements define: |
| |
| * The governance hierarchy | * The governance hierarchy |
| * The relationship between a Test Environment and its governing Domain | * The governing Authorities |
| * The applicable governance roles | * The Governance Domains |
| | * The relationship between each Test Environment and its Governance Domain |
| | * The applicable Actors and Roles |
| | * The applicable responsibilities |
| | * The applicable decision rights |
| * The governed Test Environment operations | * The governed Test Environment operations |
| | * Governance Policy application |
| * Governance Policy inheritance | * Governance Policy inheritance |
| * Governance Policy precedence | * Governance Policy precedence |
| * Authorization decisions | * Authorization decisions |
| * Tenancy isolation | * Tenancy isolation |
| * Test Environment lifecycle governance | * Test Environment Operational Lifecycle governance |
| * Governance records | * Governance records |
| * Governance Evidence | * Governance Evidence |
| * Governance decision [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] | * Governance decision Provenance |
| * Governance decision [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] | * Governance decision Traceability |
| |
| Material changes should receive review and should update the verification criteria, source records, supporting requirements, and Issues section. | Material changes receive review and update the verification criteria, source records, supporting requirements, and Issues section. |
| |
| To reference this requirement Statement from another Wiki page, insert: | To reference this requirement Statement from another Wiki page, insert: |