{
  "schema": "compliance-crosswalk/v1",
  "tool": "phishprobe",
  "frameworks": [
    {
      "id": "ISO27001",
      "name": "ISO/IEC 27001:2022",
      "controls": [
        { "ref": "A.5.13", "name": "Labelling of information",              "how": "Flags brand-impersonation attempts against monitored assets.", "coverage": "supports" },
        { "ref": "A.5.24", "name": "Information security incident management planning", "how": "AnalysisReport is a per-incident evidence artefact.", "coverage": "supports" }
      ]
    },
    {
      "id": "NIS2",
      "name": "NIS2 Directive (Dir. 2022/2555)",
      "controls": [
        { "ref": "Art. 21 §2(g)", "name": "Basic cyber hygiene practices and cybersecurity training", "how": "Detection reports feed phishing-awareness programmes.", "coverage": "supports" }
      ]
    }
  ]
}
