Differences
This shows you the differences between two versions of the page.
| Both sides previous revision Previous revision Next revision | Previous revision | ||
| dido:03-dido-te:99-annexes:annex-c-requirements:03-functional-requirements:03-03-twin-node-requirements:twin-009-control-twin-interaction:twin-009c-require-authorization-for-resource-state-changes [2026/08/22 14:21] – removed - external edit (Unknown date) 127.0.0.1 | dido:03-dido-te:99-annexes:annex-c-requirements:03-functional-requirements:03-03-twin-node-requirements:twin-009-control-twin-interaction:twin-009c-require-authorization-for-resource-state-changes [2026/08/22 14:26] (current) – nick_dido | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== TWIN-009c — Require Authorization for Resource State Changes ====== | ||
| + | [[dido: | ||
| + | |||
| + | ===== Statement ===== | ||
| + | |||
| + | The [[dido: | ||
| + | |||
| + | ===== Source ===== | ||
| + | |||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | |||
| + | ===== Rationale ===== | ||
| + | |||
| + | A permitted interaction may change the state of a [[dido: | ||
| + | |||
| + | Permission to perform an interaction does not establish authority to change Resource state. | ||
| + | |||
| + | Requiring authorization establishes a separate control decision for a Resource state change. Technical capability, connectivity, | ||
| + | |||
| + | This requirement establishes the authorization prerequisite. TWIN-009d separately prevents an unauthorized interaction from changing Resource state. | ||
| + | |||
| + | ===== Applies To ===== | ||
| + | |||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | * [[dido: | ||
| + | |||
| + | ===== Verification ===== | ||
| + | |||
| + | Verification confirms that: | ||
| + | |||
| + | - Each permitted interaction that changes Resource state requires authorization. | ||
| + | - Interaction permission does not substitute for authorization. | ||
| + | - Interaction direction does not substitute for authorization. | ||
| + | - Technical connectivity or interface access does not establish authorization. | ||
| + | - The authorization requirement is associated with the Resource whose state may change. | ||
| + | - The authorization requirement is traceable to the governing Configuration. | ||
| + | |||
| + | Verification includes at least one permitted interaction that changes Resource state and confirms that authorization is required independently of interaction permission. | ||
| + | |||
| + | ===== Traceability ===== | ||
| + | |||
| + | {{backlinks> | ||
| + | |||
| + | ===== ConOps Relationship ===== | ||
| + | |||
| + | This requirement establishes the authorization prerequisite for a permitted interaction that changes Resource state. | ||
| + | |||
| + | TWIN-009d enforces that prerequisite by preventing an unauthorized interaction from changing Resource state. | ||
| + | |||
| + | ===== Delivery Phase ===== | ||
| + | |||
| + | TBD | ||
| + | |||
| + | ===== Requirement Status ===== | ||
| + | |||
| + | Draft | ||
| + | |||
| + | ===== Statement Reference ===== | ||
| + | |||
| + | <code dokuwiki> | ||
| + | {{section> | ||
| + | </ | ||
| + | |||
| + | ---- | ||
| + | |||
| + | <WRAP centeralign> | ||
| + | © 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc. | ||
| + | </ | ||