Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
dido:03-dido-te:99-annexes:annex-c-requirements:01-mission-objectives:mo-001 [2026/08/04 02:55] – created nick_didodido:03-dido-te:99-annexes:annex-c-requirements:01-mission-objectives:mo-001 [2026/08/05 01:36] (current) – [Delivery Phase] nick_dido
Line 5: Line 5:
 ===== Statement ===== ===== Statement =====
  
-DIDO-TE SHALL restrict each operation on a Test Environment according to the Governance Policies of the Test Environment's governing [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domain]].+[[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] SHALL maintain each [[dido:99_annexes:annex-b-terms-and-definitions:t:test_environment|Test Environment]] as [[dido:99_annexes:annex-b-terms-and-definitions:g:governed|Governed]] throughout its [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]].
  
 ===== Source ===== ===== Source =====
Line 21: Line 21:
   * ''REQ-0086 — Substrate as a governed object with a recorded lifecycle''   * ''REQ-0086 — Substrate as a governed object with a recorded lifecycle''
  
-The source requirements establish the governance hierarchy, governance roles, Governance Policies, authorization boundaries, tenancy boundaries, Domain ownership of Test Environments, and governance of supporting infrastructure.+The Original Requirements establish mission-level intent concerning:
  
-MO-001 expresses the common mission-level outcome. The detailed governance, authorization, isolation, environment ownership, and lifecycle obligations remain separate Operational, Functional, Security, Logging and Auditing, and Data Management Requirements.+  * A governance hierarchy 
 +  * Governing [[dido:99_annexes:annex-b-terms-and-definitions:a:authority|Authorities]] 
 +  * Governance organizations 
 +  * Governance [[dido:99_annexes:annex-b-terms-and-definitions:r:role|Roles]] 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_domain|Governance Domains]] 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_policy|Governance Policies]] 
 +  * Membership decisions 
 +  * Authorization boundaries 
 +  * Tenancy boundaries 
 +  * Test Environment governance 
 +  * Supporting-infrastructure governance 
 +  * Operational Lifecycle governance 
 + 
 +MO-001 expresses the common mission-level outcome that each Test Environment remains Governed throughout its Operational Lifecycle. 
 + 
 +The supporting Operational, Functional, Security, Logging and Auditing, and Data Management requirements define the independently verifiable obligations governing: 
 + 
 +  * Governance structures 
 +  * Authority 
 +  * Role assignments 
 +  * Governance Policy application 
 +  * Authorization 
 +  * Isolation 
 +  * Test Environment ownership 
 +  * Operational Lifecycle transitions 
 +  * Governance records 
 +  * Governance Evidence
  
 ===== Rationale ===== ===== Rationale =====
  
-A Test Environment can consume infrastructure, execute software, exchange information, create Evidence, access protected resources, and affect systems operated by multiple organizations.+A Test Environment can:
  
-DIDO-TE requires an explicit governance context for each Test Environment so that DIDO-TE can determine:+  * Allocate and consume [[dido:99_annexes:annex-b-terms-and-definitions:r:resource|Resources]] 
 +  * Use [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_resource|Operational Resources]] 
 +  * Operate [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Nodes]] 
 +  * Operate [[dido:99_annexes:annex-b-terms-and-definitions:n:node_set|Node Sets]] 
 +  * Use [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_target|Deployment Targets]] 
 +  * Perform [[dido:99_annexes:annex-b-terms-and-definitions:t:test_execution|Test Execution]] 
 +  * Execute software 
 +  * Exchange information 
 +  * Access protected Resources 
 +  * Create [[dido:99_annexes:annex-b-terms-and-definitions:t:test_result|Test Results]] 
 +  * Create [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] 
 +  * Affect systems operated by multiple [[dido:99_annexes:annex-b-terms-and-definitions:o:organization|Organizations]]
  
-  * Which [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domain]] governs the Test Environment +Each Test Environment requires an explicit governance context that identifies:
-  * Which Governance Policies apply +
-  * Which principals may perform each operation +
-  * Which resources the Test Environment may use +
-  * Which information the Test Environment may access +
-  * Which operational boundaries apply +
-  * Which records DIDO-TE must preserve +
-  * Which approvals DIDO-TE requires +
-  * Which organization remains accountable for the Test Environment+
  
-Governance applies throughout the Test Environment lifecycle. Governance does not end after DIDO-TE creates or provisions the Test Environment.+  * The governing Authority 
 +  * The applicable Governance Domain 
 +  * The governed Test Environment 
 +  * The applicable scope 
 +  * The applicable Organizations 
 +  * The applicable [[dido:99_annexes:annex-b-terms-and-definitions:c:community_of_interest|Communities of Interest]] 
 +  * The responsible [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actors]] 
 +  * The applicable Roles 
 +  * The applicable responsibilities 
 +  * The applicable decision rights 
 +  * The applicable Governance Policies 
 +  * The applicable approval processes 
 +  * The applicable change-control processes 
 +  * The applicable exception and waiver processes 
 +  * The applicable enforcement mechanisms 
 +  * The applicable accountability mechanisms 
 +  * The required Evidence 
 +  * The required [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] 
 +  * The required [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]
  
-The detailed requirements define the operations subject to governance and the mechanism for determining the applicable Governance Policies. MO-001 establishes the mission-level obligation to apply those policies consistently.+Governance applies throughout the Operational Lifecycle of the Test Environment. Governance does not end after DIDO-TE creates, provisions, deploys, or activates the Test Environment. 
 + 
 +The supporting requirements define how DIDO-TE establishes, applies, evaluates, records, and enforces the applicable governance context. MO-001 establishes the mission-level outcome that the Test Environment remains Governed.
  
 ===== Applies To ===== ===== Applies To =====
Line 49: Line 98:
 This requirement applies to: This requirement applies to:
  
-  * DIDO-TE +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] 
-  * Test Environments+  * [[dido:99_annexes:annex-b-terms-and-definitions:t:test_environment|Test Environments]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:d:distributed_system|Distributed Systems]]   * [[dido:99_annexes:annex-b-terms-and-definitions:d:distributed_system|Distributed Systems]]
-  * Governing [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domains]] +  * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_domain|Governance Domains]] 
-  * Governance Policies +  * Governing [[dido:99_annexes:annex-b-terms-and-definitions:a:authority|Authorities]] 
-  * Governance roles +  * [[dido:99_annexes:annex-b-terms-and-definitions:o:organization|Organizations]] 
-  * Authorized principals+  * [[dido:99_annexes:annex-b-terms-and-definitions:c:community_of_interest|Communities of Interest]] 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:a:actor|Actors]] 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:r:role|Roles]] 
 +  * [[dido:99_annexes:annex-b-terms-and-definitions:g:governance_policy|Governance Policies]]
   * Test Environment operations   * Test Environment operations
-  * Test Environment resources +  * Test Environment [[dido:99_annexes:annex-b-terms-and-definitions:r:resource|Resources]] 
-  * Nodes +  * [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_resource|Operational Resources]] 
-  * Node Sets +  * [[dido:99_annexes:annex-b-terms-and-definitions:n:node|Nodes]] 
-  * Deployment Targets +  * [[dido:99_annexes:annex-b-terms-and-definitions:n:node_set|Node Sets]] 
-  * Virtual Networks +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_target|Deployment Targets]] 
-  * Test Definitions +  * [[dido:99_annexes:annex-b-terms-and-definitions:t:test_definition|Test Definitions]] 
-  * Test Runs +  * [[dido:99_annexes:annex-b-terms-and-definitions:t:test_run|Test Runs]] 
-  * Test Results +  * [[dido:99_annexes:annex-b-terms-and-definitions:t:test_result|Test Results]] 
-  * Baseline Results +  * [[dido:99_annexes:annex-b-terms-and-definitions:v:validation_decision|Validation Decisions]]
-  * Validation Decisions+
   * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]   * [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]   * [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]]
Line 73: Line 124:
   * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]]   * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]   * [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environments]]
 +  * The [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] of each Test Environment
  
 ===== Verification ===== ===== Verification =====
Line 78: Line 130:
 Verification confirms that: Verification confirms that:
  
-  - Each Test Environment identifies exactly one governing [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domain]] +  - Each Test Environment has an identified governance context 
-  - DIDO-TE identifies the Governance Policies applicable to the Test Environment +  - The governance context identifies the governing Authority 
-  - DIDO-TE identifies the operations governed by each applicable Governance Policy +  The governance context identifies the applicable Governance Domain 
-  - DIDO-TE identifies the principal requesting each Test Environment operation +  - The governance context identifies the governed Test Environment 
-  - DIDO-TE evaluates each requested operation against the applicable Governance Policies +  - The governance context identifies its applicable scope 
-  - DIDO-TE permits an operation when the applicable Governance Policies authorize the requesting principal to perform the operation +  The governance context identifies the applicable Organizations and Communities of Interest 
-  - DIDO-TE refuses an operation when the applicable Governance Policies do not authorize the requesting principal to perform the operation +  - The governance context identifies the applicable Actors and Roles 
-  - DIDO-TE refuses an operation when the Test Environment does not identify a valid governing Domain +  The governance context identifies the applicable responsibilities and decision rights 
-  - DIDO-TE prevents a principal governed by one tenancy boundary from operating a Test Environment governed by another tenancy boundary unless the applicable Governance Policies explicitly authorize the operation +  - The governance context identifies the applicable Governance Policies 
-  - DIDO-TE applies the Governance Policies throughout the Test Environment lifecycle +  - The governance context identifies the applicable approval processes 
-  - DIDO-TE records the governing Domainrequesting principal, requested operation, authorization result, operation result, and applicable Governance Policies +  The governance context identifies the applicable change-control processes 
-  - The verification record preserves [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] among the Test Environment, governing Domain, applicable Governance Policies, requesting principalrequested operationauthorization resultoperation result, and supporting [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]]+  - The governance context identifies the applicable exception and waiver processes 
 +  - The governance context identifies the applicable enforcement mechanisms 
 +  - The governance context identifies the applicable accountability and review processes 
 +  - DIDO-TE applies the governance context to Test Environment operations 
 +  - DIDO-TE evaluates each governed Test Environment operation according to the applicable Governance Policies 
 +  - DIDO-TE applies the governance context throughout the Operational Lifecycle of the Test Environment 
 +  - DIDO-TE applies the governance context in ConnectedDisconnected, and Air-Gapped Environments 
 +  - DIDO-TE preserves the Evidence required to demonstrate application of the governance context 
 +  DIDO-TE preserves Provenance for governance decisions and Test Environment operations 
 +  The verification record preserves Traceability among the Test Environment, governing Authority, Governance Domain, Actors, Roles, Governance Policies, governance decisionsTest Environment operationsEvidenceand verification result
  
 ===== Referenced By ===== ===== Referenced By =====
Line 99: Line 160:
 ===== Delivery Phase ===== ===== Delivery Phase =====
  
-Not Assessed+<todo>TBD</todo>
  
 ===== Implementation Status ===== ===== Implementation Status =====
  
-<todo>Assess the current DIDO-TE implementation against MO-001 and its supporting Operational, Functional, Security, Logging and Auditing, and Data Management Requirements.</todo>+<todo>Assess the current DIDO-TE implementation against MO-001 and its supporting Operational, Functional, Security, Logging and Auditing, and Data Management requirements.</todo>
  
 ===== Requirement Status ===== ===== Requirement Status =====
  
-<todo>Review and approve MO-001 as a proposed Mission Objective derived from the governance and Test Environment requirements in the draft DIDO-TE Requirements Register.</todo>+<todo>Review and approve MO-001 as a proposed Mission Objective consolidated from the governance and Test Environment requirements in the draft DIDO-TE Requirements Register.</todo>
  
 ---- ----
 +
 ===== Issues ===== ===== Issues =====
  
 The following unresolved issues affect this requirement: The following unresolved issues affect this requirement:
  
-<todo>Define Test Environment in the shared DIDO Solutions Terms and Definitions corpus.</todo>+<todo>Define Governance in the shared DIDO Solutions Terms and Definitions corpus.</todo>
  
-<todo>Define Governance Policy in the shared DIDO Solutions Terms and Definitions corpus or identify the applicable controlling term.</todo>+<todo>Define the governance hierarchy applicable to DIDO-TE Test Environments.</todo> 
 + 
 +<todo>Define the relationship between a Test Environment and its governing Governance Domain.</todo> 
 + 
 +<todo>Define whether each Test Environment has one primary governing Governance Domain or can have multiple governing Governance Domains.</todo>
  
 <todo>Define the complete set of Test Environment operations governed by MO-001.</todo> <todo>Define the complete set of Test Environment operations governed by MO-001.</todo>
  
-<todo>Define how DIDO-TE determines the governing Domain for a Test Environment.</todo>+<todo>Define how DIDO-TE identifies the governing Authority for a Test Environment.</todo>
  
 <todo>Define how DIDO-TE resolves Governance Policies inherited through the governance hierarchy.</todo> <todo>Define how DIDO-TE resolves Governance Policies inherited through the governance hierarchy.</todo>
  
-<todo>Define the precedence and conflict-resolution rules for Governance Policies established at different levels of the governance hierarchy.</todo>+<todo>Define the precedence and conflict-resolution rules for Governance Policies established by different Authorities or at different levels of the governance hierarchy.</todo>
  
-<todo>Define the authorization decision required when an applicable Governance Policy is missing, invalid, unavailable, or internally inconsistent.</todo>+<todo>Define the decision required when an applicable Governance Policy is missing, invalid, unavailable, or internally inconsistent.</todo>
  
-<todo>Define the Evidence DIDO-TE preserves for each governance decision and Test Environment operation.</todo>+<todo>Define the Governance Evidence DIDO-TE preserves for each governance decision and Test Environment operation.</todo> 
 + 
 +<todo>Define the governance requirements applicable during each Test Environment Operational Lifecycle state and transition.</todo>
  
 ---- ----
 +
 ===== Notes for Editors ===== ===== Notes for Editors =====
  
-This requirement page should retain the stable requirement identifier ''MO-001''.+This requirement page retains the stable requirement identifier ''MO-001''.
  
 This page is a leaf requirement page and omits a trailing '':start'' from its namespace. This page is a leaf requirement page and omits a trailing '':start'' from its namespace.
Line 139: Line 208:
 MO-001 consolidates mission-level intent from multiple Original Requirements. MO-001 does not result from splitting a single parent requirement and therefore uses a **Source** section rather than a **Derived From** section. MO-001 consolidates mission-level intent from multiple Original Requirements. MO-001 does not result from splitting a single parent requirement and therefore uses a **Source** section rather than a **Derived From** section.
  
-Changes to the Statement should preserve:+Changes to the Statement preserve:
  
-  * DIDO-TE as the responsible actor +  * [[dido:99_annexes:annex-b-terms-and-definitions:d:dido-te|DIDO-TE]] as the responsible Actor 
-  * Each Test Environment operation as the governed activity +  * Each [[dido:99_annexes:annex-b-terms-and-definitions:t:test_environment|Test Environment]] as the governed subject 
-  * Governance Policies as the controlling rules +  * [[dido:99_annexes:annex-b-terms-and-definitions:g:governed|Governed]] as the required condition 
-  * The Test Environment's governing [[dido:99_annexes:annex-b-terms-and-definitions:d:domain|Domain]] as the source of the applicable governance context +  * The [[dido:99_annexes:annex-b-terms-and-definitions:o:operational_lifecycle|Operational Lifecycle]] as the temporal scope of the obligation
-  * Enforcement of the applicable Governance Policies as the required outcome+
  
-The supporting requirements should define:+The supporting requirements define:
  
   * The governance hierarchy   * The governance hierarchy
-  * The relationship between Test Environment and its governing Domain +  * The governing Authorities 
-  * The applicable governance roles+  * The Governance Domains 
 +  * The relationship between each Test Environment and its Governance Domain 
 +  * The applicable Actors and Roles 
 +  * The applicable responsibilities 
 +  * The applicable decision rights
   * The governed Test Environment operations   * The governed Test Environment operations
 +  * Governance Policy application
   * Governance Policy inheritance   * Governance Policy inheritance
   * Governance Policy precedence   * Governance Policy precedence
Line 158: Line 231:
   * Authorization decisions   * Authorization decisions
   * Tenancy isolation   * Tenancy isolation
-  * Test Environment lifecycle governance+  * Test Environment Operational Lifecycle governance
   * Governance records   * Governance records
   * Governance Evidence   * Governance Evidence
-  * Governance decision [[dido:99_annexes:annex-b-terms-and-definitions:p:provenance|Provenance]] +  * Governance decision Provenance 
-  * Governance decision [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]]+  * Governance decision Traceability
  
-Material changes should receive review and should update the verification criteria, source records, supporting requirements, and Issues section.+Material changes receive review and update the verification criteria, source records, supporting requirements, and Issues section.
  
 To reference this requirement Statement from another Wiki page, insert: To reference this requirement Statement from another Wiki page, insert:
  • dido/03-dido-te/99-annexes/annex-c-requirements/01-mission-objectives/mo-001.1785837304.txt.gz
  • Last modified: 2026/08/04 02:55
  • by nick_dido