ENV-002h — Enforce Security Constraints

The DIDO-TE SHALL enforce each security Constraint applicable to a Test Environment before and during Test Execution.

Security Constraints establish the protections governing access to and interaction with a Test Environment and its constituent elements.

Enforcing these Constraints protects the confidentiality, integrity, authenticity, availability, and permitted use of Test Objects, Nodes, Test Resources, communications, data, configurations, and Evidence.

Maintaining the specified security conditions prevents unauthorised access, prohibited communication, uncontrolled modification, and other security violations from affecting Test Execution or the resulting Test Results.

Verification confirms that:

  • The DIDO-TE identifies every security Constraint applicable to the Test Environment.
  • The DIDO-TE enforces each applicable security Constraint before and during Test Execution.
  • The enforced Constraints govern identity, authentication, authorisation, access, isolation, communication, data protection, integrity, and audit recording, when applicable.
  • The DIDO-TE excludes access, operations, and communications prohibited by the applicable security Constraints.
  • The DIDO-TE records security-relevant events and violations as Evidence.
  • The DIDO-TE maintains Traceability among each security Constraint, its enforcement mechanism, and the applicable Test Execution.
  • The DIDO-TE prevents Test Execution when a required security Constraint remains unsatisfied before execution.
  • The DIDO-TE identifies a security Constraint violation occurring during Test Execution and records its relationship to the affected Test Execution and Test Results.
  • A missing, unenforced, violated, or untraceable security Constraint constitutes nonconformance with this requirement.

Verification includes:

  • Inspection of the security Constraints applicable to the Test Environment
  • Inspection of the mechanisms enforcing each security Constraint
  • Inspection of identity, authentication, authorisation, access-control, isolation, communication-protection, integrity, and audit records, when applicable
  • Testing of permitted access, operations, and communications
  • Testing for the exclusion of prohibited access, operations, and communications
  • Inspection of security Evidence and Traceability records
  • A negative assessment using an unsatisfied security Constraint before Test Execution
  • Confirmation that the DIDO-TE prevents Test Execution when the Constraint remains unsatisfied
  • A negative assessment introducing a security Constraint violation during Test Execution
  • Confirmation that the DIDO-TE identifies and records the violation and its relationship to the affected Test Execution and Test Results
  • Add links to the architecture sections governing security Constraints, access control, communications protection, audit recording, and security-event handling.

Assign the applicable delivery phase.

Draft

Use the following syntax to reference this requirement’s Statement section from another DokuWiki page:

{{section>dido:03-dido-te:99-annexes:annex-c-requirements:02-test-environment-requirements:env-002-configure-test-environment:env-002h-enforce-security-constraints#Statement&noheader&nofooter&noeditbtn}}

© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.

  • dido/03-dido-te/99-annexes/annex-c-requirements/03-functional-requirements/03-01-test-environment-requirements/env-002-configure-test-environment/env-002h-enforce-security-constraints.txt
  • Last modified: 2026/08/18 12:34
  • by nick_dido