{
  "schema": "compliance-crosswalk/v1",
  "tool": "urlrecon",
  "frameworks": [
    {
      "id": "ISO27001",
      "name": "ISO/IEC 27001:2022",
      "controls": [
        { "ref": "A.8.8",  "name": "Management of technical vulnerabilities",       "how": "Findings feed vulnerability-management workflows; jfind emits promotable-to-vulnerability categories.", "coverage": "supports" },
        { "ref": "A.8.9",  "name": "Configuration management",                       "how": "headers / tls / dnssec / cors modules identify misconfiguration.", "coverage": "supports" },
        { "ref": "A.5.7",  "name": "Threat intelligence",                            "how": "Passive OSINT reconnaissance surface.", "coverage": "supports" }
      ]
    },
    {
      "id": "PCI-DSS",
      "name": "PCI-DSS v4.0",
      "controls": [
        { "ref": "Req. 2.2", "name": "Secure configurations",     "how": "TLS + header modules identify insecure defaults.", "coverage": "supports" },
        { "ref": "Req. 11.3","name": "External vulnerability scanning", "how": "Passive external-surface enumeration.", "coverage": "supports" }
      ]
    }
  ]
}
