{
  "schema": "compliance-crosswalk/v1",
  "tool": "cmdb",
  "frameworks": [
    {
      "id": "DORA",
      "name": "Digital Operational Resilience Act (Reg. 2022/2554)",
      "controls": [
        { "ref": "Art. 8", "name": "Identification of ICT-supported business functions + underlying assets", "how": "Asset inventory + business-function linkage table.", "coverage": "evidences" }
      ]
    },
    {
      "id": "ISO27001",
      "name": "ISO/IEC 27001:2022",
      "controls": [
        { "ref": "A.5.9",  "name": "Inventory of information + other associated assets", "how": "Asset table with ownership + criticality metadata.", "coverage": "evidences" },
        { "ref": "A.5.10", "name": "Acceptable use of information + other associated assets", "how": "Records asset owner + acceptable-use metadata.", "coverage": "supports" }
      ]
    },
    {
      "id": "NIS2",
      "name": "NIS2 Directive (Dir. 2022/2555)",
      "controls": [
        { "ref": "Art. 21 §2(d)", "name": "Supply-chain security including security-related aspects of relationships", "how": "Records third-party dependencies per asset.", "coverage": "supports" }
      ]
    }
  ]
}
