{
  "schema": "compliance-crosswalk/v1",
  "tool": "dossier",
  "frameworks": [
    {
      "id": "ISO27001",
      "name": "ISO/IEC 27001:2022",
      "controls": [
        { "ref": "A.5.24", "name": "Information security incident management planning and preparation", "how": "incident template renders IR playbook artefacts as HTML / Markdown / dossier-ir.", "coverage": "supports" },
        { "ref": "A.5.35", "name": "Independent review of information security",                       "how": "pentest template renders external-assessment deliverables.", "coverage": "supports" },
        { "ref": "A.8.34", "name": "Protection of information systems during audit and testing",       "how": "pentest template includes rules-of-engagement + engagement-window sections.", "coverage": "supports" }
      ]
    },
    {
      "id": "DORA",
      "name": "Digital Operational Resilience Act",
      "controls": [
        { "ref": "Art. 6",  "name": "ICT risk-management framework",              "how": "gap-assessment template is fed by complymap's gap matrix.",            "coverage": "supports" },
        { "ref": "Art. 24", "name": "Advanced testing (TLPT)",                    "how": "pentest template consumes tiberscope brief + plan artefacts.",         "coverage": "supports" }
      ]
    }
  ]
}
