{"id":1036,"date":"2026-08-31T06:19:20","date_gmt":"2026-08-31T06:19:20","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1036"},"modified":"2026-08-31T06:19:20","modified_gmt":"2026-08-31T06:19:20","slug":"rbi-cybersecurity-audit-checklist","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/rbi-cybersecurity-audit-checklist\/","title":{"rendered":"RBI Cybersecurity Audit Checklist: 12 Essential Checks"},"content":{"rendered":"\n<!-- WordPress Custom HTML block. Add the page title and featured image separately in WordPress. -->\n<style>\n.osto-rbi-audit{--blue:#1c267a;--ink:#171a2f;--muted:#596078;--pale:#f3f5ff;--line:#cfd5ee;max-width:920px;margin:auto;color:var(--ink);font-family:Inter,system-ui,-apple-system,\"Segoe UI\",Arial,sans-serif;font-size:17px;line-height:1.75}.osto-rbi-audit *{box-sizing:border-box}.osto-rbi-audit h2{font-size:30px;line-height:1.22;letter-spacing:-.5px;margin:44px 0 15px}.osto-rbi-audit h3{font-size:21px;line-height:1.35;margin:27px 0 9px}.osto-rbi-audit p{margin:0 0 18px}.osto-rbi-audit a{color:var(--blue);text-decoration:underline;text-underline-offset:3px}.osto-rbi-audit .intro{font-size:19px;color:var(--muted);margin:4px 0 18px}.osto-rbi-audit .tldr,.osto-rbi-audit .callout{border:1px solid var(--blue);background:var(--pale);border-radius:14px;padding:21px 23px;margin:0 0 27px}.osto-rbi-audit .tldr b{display:block;color:var(--blue);font-size:14px;letter-spacing:.11em;text-transform:uppercase;margin-bottom:6px}.osto-rbi-audit .toc{background:#fff;border:1px solid var(--line);border-radius:14px;padding:20px 23px}.osto-rbi-audit .toc strong{display:block;margin-bottom:8px}.osto-rbi-audit .toc ol{margin:0;padding-left:22px;columns:2;column-gap:34px}.osto-rbi-audit .toc li{margin:4px 0;break-inside:avoid}.osto-rbi-audit .fig{margin:27px 0;border:1px solid var(--line);border-radius:18px;overflow:hidden;background:#fff}.osto-rbi-audit .fig-head{padding:17px 21px;border-bottom:1px solid var(--line)}.osto-rbi-audit .fig-head strong,.osto-rbi-audit .fig-head span{display:block}.osto-rbi-audit .fig-head strong{font-size:20px;color:var(--blue)}.osto-rbi-audit .fig-head span{font-size:14px;color:var(--muted)}.osto-rbi-audit svg{display:block;width:100%;height:auto}.osto-rbi-audit .table-wrap{overflow-x:auto;margin:22px 0}.osto-rbi-audit table{border-collapse:separate;border-spacing:0;width:100%;min-width:700px;border:1px solid var(--line);border-radius:13px;overflow:hidden}.osto-rbi-audit th,.osto-rbi-audit td{padding:13px 14px;text-align:left;vertical-align:top;border-bottom:1px solid var(--line)}.osto-rbi-audit th{background:var(--blue);color:#fff;font-size:14px}.osto-rbi-audit tr:last-child td{border-bottom:0}.osto-rbi-audit td:first-child{font-weight:700;color:var(--blue)}.osto-rbi-audit .audit-list{margin:18px 0 28px;padding:0;list-style:none;counter-reset:audit}.osto-rbi-audit .audit-list li{counter-increment:audit;position:relative;padding:11px 0 11px 42px;border-bottom:1px solid var(--line)}.osto-rbi-audit .audit-list li:before{content:counter(audit);position:absolute;left:0;top:12px;width:27px;height:27px;border-radius:50%;background:var(--blue);color:#fff;font-size:13px;font-weight:700;line-height:27px;text-align:center}.osto-rbi-audit .audit-list strong{color:var(--blue)}.osto-rbi-audit .plain-list{margin:8px 0 22px;padding-left:22px}.osto-rbi-audit .plain-list li{margin:6px 0}.osto-rbi-audit .callout{background:#fff}.osto-rbi-audit .callout strong{color:var(--blue)}.osto-rbi-audit .cta{margin:46px 0 38px;padding:31px;border-radius:20px;background:var(--blue);color:#fff}.osto-rbi-audit .cta h3{margin:0 0 8px;color:#fff;font-size:27px}.osto-rbi-audit .cta p{color:#eef1ff}.osto-rbi-audit .cta a{display:inline-block;margin-top:4px;padding:11px 18px;border-radius:9px;background:#fff;color:var(--blue);font-weight:750;text-decoration:none}.osto-rbi-audit .faq{border-top:1px solid var(--line)}.osto-rbi-audit details{border-bottom:1px solid var(--line)}.osto-rbi-audit summary{position:relative;cursor:pointer;list-style:none;padding:20px 50px 20px 0;font-weight:700}.osto-rbi-audit summary::-webkit-details-marker{display:none}.osto-rbi-audit summary:after{content:\"+\";position:absolute;right:2px;top:15px;width:31px;height:31px;border-radius:50%;background:var(--pale);color:var(--blue);font-size:24px;line-height:28px;text-align:center}.osto-rbi-audit details[open] summary:after{content:\"\u2212\"}.osto-rbi-audit details p{padding:0 50px 18px 0;color:var(--muted)}.osto-rbi-audit .sources{font-size:14px;color:var(--muted)}\n@media(max-width:720px){.osto-rbi-audit h2{font-size:27px}.osto-rbi-audit .intro{font-size:18px}.osto-rbi-audit .toc ol{columns:1}.osto-rbi-audit .fig{overflow-x:auto}.osto-rbi-audit .fig svg{min-width:680px}.osto-rbi-audit .cta{padding:25px}}\n<\/style>\n<article class=\"osto-rbi-audit\">\n  <p class=\"intro\">This RBI cybersecurity audit checklist explains what regulated entities should examine across governance, technology, resilience, third parties and assurance. It also shows the evidence an auditor should expect, helping teams move from policy statements to controls that can actually be verified.<\/p>\n  <section class=\"tldr\"><b>TL;DR<\/b><p>An <strong>RBI cybersecurity audit checklist<\/strong> should test both control design and operating effectiveness. The auditor should verify Board oversight, asset and risk registers, access controls, security monitoring, vulnerability management, application security, incident response, business continuity, vendor governance and closure of earlier findings.<\/p><p>RBI does not prescribe one identical checklist for every regulated entity. Banks, NBFCs, CICs, payment operators and other entities must first identify the directions applicable to their category, scale, digital depth and services. This checklist provides a practical baseline, not a substitute for that applicability assessment.<\/p><\/section>\n\n  <nav class=\"toc\" aria-label=\"Table of contents\"><strong>On this page<\/strong><ol><li><a href=\"#meaning\">What an RBI cybersecurity audit covers<\/a><\/li><li><a href=\"#applicability\">Who should use this checklist<\/a><\/li><li><a href=\"#prepare\">Documents to prepare<\/a><\/li><li><a href=\"#checklist\">12-domain audit checklist<\/a><\/li><li><a href=\"#evidence\">Evidence matrix<\/a><\/li><li><a href=\"#findings\">How to manage findings<\/a><\/li><li><a href=\"#frequency\">Audit frequency<\/a><\/li><li><a href=\"#osto\">How Osto helps<\/a><\/li><li><a href=\"#faq\">FAQs<\/a><\/li><\/ol><\/nav>\n\n  <h2 id=\"meaning\">What does an RBI cybersecurity audit cover?<\/h2>\n  <p>An RBI-aligned cybersecurity audit evaluates whether an entity has identified its technology and cyber risks, implemented proportionate controls, monitored those controls and retained reliable evidence. It is broader than a vulnerability scan or annual penetration test. A complete review connects governance decisions to technical implementation and tests whether the controls worked during the audit period.<\/p>\n  <p>The RBI Information Technology Governance, Risk, Controls and Assurance Practices Directions require covered regulated entities to maintain an independent Information Systems Audit function, use a risk-based audit approach and place appropriate oversight with the Audit Committee of the Board. Current entity-specific directions may create additional requirements, so the audit universe should be mapped before fieldwork begins.<\/p>\n\n  <div class=\"fig\" role=\"img\" aria-label=\"RBI cybersecurity audit lifecycle from applicability mapping to closure evidence\"><div class=\"fig-head\"><strong>The RBI cybersecurity audit lifecycle<\/strong><span>A defensible audit connects scope, testing, remediation and governance.<\/span><\/div>\n  <svg viewBox=\"0 0 900 260\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><defs><marker id=\"audit-arrow\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0 0L9 4.5 0 9Z\" fill=\"#1c267a\"\/><\/marker><\/defs><g font-family=\"Inter,Arial,sans-serif\"><g stroke=\"#1c267a\" stroke-width=\"4\" marker-end=\"url(#audit-arrow)\"><path d=\"M188 130H220\"\/><path d=\"M408 130H440\"\/><path d=\"M628 130H660\"\/><\/g><g fill=\"#f3f5ff\" stroke=\"#1c267a\" stroke-width=\"2\"><rect x=\"12\" y=\"55\" width=\"176\" height=\"150\" rx=\"16\"\/><rect x=\"220\" y=\"55\" width=\"188\" height=\"150\" rx=\"16\"\/><rect x=\"440\" y=\"55\" width=\"188\" height=\"150\" rx=\"16\"\/><rect x=\"660\" y=\"55\" width=\"228\" height=\"150\" rx=\"16\"\/><\/g><g text-anchor=\"middle\"><g fill=\"#1c267a\" font-size=\"18\" font-weight=\"700\"><text x=\"100\" y=\"98\">Map<\/text><text x=\"314\" y=\"98\">Test<\/text><text x=\"534\" y=\"98\">Correct<\/text><text x=\"774\" y=\"98\">Govern<\/text><\/g><g fill=\"#596078\" font-size=\"13\"><text x=\"100\" y=\"128\"><tspan x=\"100\">Applicable directions,<\/tspan><tspan x=\"100\" dy=\"20\">assets and risks<\/tspan><\/text><text x=\"314\" y=\"128\"><tspan x=\"314\">Design and operating<\/tspan><tspan x=\"314\" dy=\"20\">effectiveness<\/tspan><\/text><text x=\"534\" y=\"128\"><tspan x=\"534\">Owners, deadlines<\/tspan><tspan x=\"534\" dy=\"20\">and retesting<\/tspan><\/text><text x=\"774\" y=\"128\"><tspan x=\"774\">ACB reporting and<\/tspan><tspan x=\"774\" dy=\"20\">closure evidence<\/tspan><\/text><\/g><\/g><\/g><\/svg><\/div>\n\n  <h2 id=\"applicability\">Who should use this RBI cybersecurity audit checklist?<\/h2>\n  <p>The checklist is designed for security, compliance, internal audit, technology risk and leadership teams at RBI-regulated financial entities. It is useful for readiness reviews, internal audits, vendor-led audits and remediation planning.<\/p>\n  <div class=\"callout\"><strong>Start with applicability:<\/strong> identify the entity category and current directions that apply. A commercial bank, co-operative bank, NBFC, credit information company and non-bank payment system operator may have different governance, testing, reporting and resilience obligations.<\/div>\n  <p>For NBFC-specific requirements, use Osto\u2019s guide to <a href=\"https:\/\/www.osto.one\/resources\/blog\/rbi-cybersecurity-compliance-for-nbfcs\/\">RBI cybersecurity compliance for NBFCs<\/a>. Digital lenders should also review the <a href=\"https:\/\/www.osto.one\/resources\/blog\/rbi-digital-lending-security-requirements\/\">RBI digital lending security requirements<\/a>.<\/p>\n\n  <h2 id=\"prepare\">What to prepare before the audit<\/h2>\n  <p>Collect records for the full review period, not only the latest policy versions. The core evidence set includes:<\/p>\n  <ul class=\"plain-list\"><li>Approved IT and cybersecurity policies, committee minutes and risk reports<\/li><li>Asset, application, API and data inventories with criticality ratings<\/li><li>Access reviews, logs, VA\/PT reports, patch records and remediation evidence<\/li><li>Incident records, DR tests, backup restorations and vendor assessments<\/li><\/ul>\n\n  <h2 id=\"checklist\">12-point RBI cybersecurity audit checklist<\/h2>\n  <p>Test whether each control is documented, operating and supported by dated evidence. A verbal \u201cyes\u201d should not be treated as a passed control.<\/p>\n  <ol class=\"audit-list\"><li><strong>Governance:<\/strong> approved policies, clear accountability and Board-level risk oversight.<\/li><li><strong>Assets and data:<\/strong> complete inventories, ownership and criticality classification.<\/li><li><strong>Cyber risk:<\/strong> current assessments, treatment owners and residual-risk approval.<\/li><li><strong>Identity:<\/strong> MFA, least privilege, timely access removal and privileged monitoring.<\/li><li><strong>Infrastructure:<\/strong> secure baselines, encryption, EDR, segmentation and supported systems.<\/li><li><strong>Vulnerability management:<\/strong> scheduled scanning, independent VA\/PT, remediation and retesting.<\/li><li><strong>Applications and APIs:<\/strong> secure SDLC, code testing, secrets protection and release checks.<\/li><li><strong>Monitoring:<\/strong> protected logs, relevant detection rules and investigated alerts.<\/li><li><strong>Incident response:<\/strong> defined escalation, tested playbooks and reporting readiness.<\/li><li><strong>Resilience:<\/strong> realistic RTO\/RPO, DR exercises and successful backup restoration.<\/li><li><strong>Third parties:<\/strong> due diligence, security clauses, monitoring and exit planning.<\/li><li><strong>Audit closure:<\/strong> independent assurance, accountable owners and verified remediation.<\/li><\/ol>\n\n  <div class=\"fig\" role=\"img\" aria-label=\"Twelve RBI cybersecurity audit domains arranged in three control layers\"><div class=\"fig-head\"><strong>Three layers of audit assurance<\/strong><span>The strongest audits connect leadership, protective controls and recoverability.<\/span><\/div>\n  <svg viewBox=\"0 0 900 410\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><g font-family=\"Inter,Arial,sans-serif\"><rect x=\"30\" y=\"25\" width=\"840\" height=\"105\" rx=\"16\" fill=\"#1c267a\"\/><rect x=\"30\" y=\"152\" width=\"840\" height=\"105\" rx=\"16\" fill=\"#f3f5ff\" stroke=\"#1c267a\" stroke-width=\"2\"\/><rect x=\"30\" y=\"279\" width=\"840\" height=\"105\" rx=\"16\" fill=\"#fff\" stroke=\"#1c267a\" stroke-width=\"2\"\/><g font-size=\"16\" font-weight=\"700\"><text x=\"66\" y=\"84\" fill=\"#fff\">GOVERN<\/text><text x=\"66\" y=\"211\" fill=\"#1c267a\">PROTECT<\/text><text x=\"66\" y=\"338\" fill=\"#1c267a\">RECOVER<\/text><\/g><g font-size=\"14\" text-anchor=\"middle\"><g fill=\"#fff\"><text x=\"300\" y=\"105\">Governance<\/text><text x=\"475\" y=\"105\">Assets and risk<\/text><text x=\"650\" y=\"105\">Third parties<\/text><text x=\"800\" y=\"105\">Audit<\/text><\/g><g fill=\"#171a2f\"><text x=\"300\" y=\"232\">Identity<\/text><text x=\"475\" y=\"232\">Infrastructure<\/text><text x=\"650\" y=\"232\">Vulnerability<\/text><text x=\"800\" y=\"232\">Apps<\/text><text x=\"300\" y=\"359\">Monitoring<\/text><text x=\"475\" y=\"359\">Incidents<\/text><text x=\"650\" y=\"359\">BCP and DR<\/text><text x=\"800\" y=\"359\">Backups<\/text><\/g><\/g><g><g fill=\"#fff\" opacity=\".18\"><circle cx=\"300\" cy=\"62\" r=\"17\"\/><circle cx=\"475\" cy=\"62\" r=\"17\"\/><circle cx=\"650\" cy=\"62\" r=\"17\"\/><circle cx=\"800\" cy=\"62\" r=\"17\"\/><\/g><g fill=\"#1c267a\" opacity=\".10\"><circle cx=\"300\" cy=\"189\" r=\"17\"\/><circle cx=\"475\" cy=\"189\" r=\"17\"\/><circle cx=\"650\" cy=\"189\" r=\"17\"\/><circle cx=\"800\" cy=\"189\" r=\"17\"\/><circle cx=\"300\" cy=\"316\" r=\"17\"\/><circle cx=\"475\" cy=\"316\" r=\"17\"\/><circle cx=\"650\" cy=\"316\" r=\"17\"\/><circle cx=\"800\" cy=\"316\" r=\"17\"\/><\/g><g fill=\"none\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"3.5\"><path d=\"M291 62l6 6 12-14M466 62l6 6 12-14M641 62l6 6 12-14M791 62l6 6 12-14\" stroke=\"#fff\"\/><path d=\"M291 189l6 6 12-14M466 189l6 6 12-14M641 189l6 6 12-14M791 189l6 6 12-14M291 316l6 6 12-14M466 316l6 6 12-14M641 316l6 6 12-14M791 316l6 6 12-14\" stroke=\"#1c267a\"\/><\/g><\/g><\/g><\/svg><\/div>\n\n  <h2 id=\"evidence\">RBI cybersecurity audit evidence matrix<\/h2>\n  <p>Sample evidence across the complete audit period, with priority given to critical systems and privileged activity.<\/p>\n  <div class=\"table-wrap\"><table><thead><tr><th>Area<\/th><th>Evidence<\/th><th>Auditor check<\/th><\/tr><\/thead><tbody><tr><td>Governance<\/td><td>Policies, minutes and risk acceptances<\/td><td>Approval, review dates and tracked actions<\/td><\/tr><tr><td>Access<\/td><td>User lists, access reviews and PAM logs<\/td><td>Leavers, excessive rights and privileged use<\/td><\/tr><tr><td>Security testing<\/td><td>VA\/PT reports, tickets and retest records<\/td><td>Scope, open risk and verified closure<\/td><\/tr><tr><td>Resilience<\/td><td>Incident, DR and restoration records<\/td><td>Response readiness and achieved RTO\/RPO<\/td><\/tr><tr><td>Vendors<\/td><td>Due diligence, contracts and service reports<\/td><td>Risk tiering and enforceable security clauses<\/td><\/tr><\/tbody><\/table><\/div>\n\n  <h2 id=\"findings\">How should audit findings be managed?<\/h2>\n  <p>Every finding needs evidence, risk, root cause, an accountable owner and a target date. Closure should be independently validated, with technical weaknesses retested and overdue findings escalated through the defined governance route.<\/p>\n  <div class=\"callout\"><strong>Avoid a common audit gap:<\/strong> do not treat a VAPT certificate as complete assurance. Retain the detailed report, risk-ranked findings, remediation evidence and independent retest status. Osto\u2019s guide to <a href=\"https:\/\/www.osto.one\/resources\/blog\/how-to-read-a-vapt-report\/\">reading a VAPT report<\/a> explains what decision-makers should verify.<\/div>\n\n  <h2 id=\"frequency\">How often should an RBI cybersecurity audit be conducted?<\/h2>\n  <p>Audit frequency should come from the applicable RBI direction, the entity\u2019s risk-based IS audit plan and the criticality of the system. Covered regulated entities should maintain an audit plan that considers prior findings, major changes, new services, incidents, outsourcing and the evolving threat environment.<\/p>\n  <p>VA\/PT frequency is a separate decision. Under the RBI IT Governance Directions, applicable critical or DMZ assets require vulnerability assessment at least once every six months and penetration testing at least once every 12 months, with lifecycle testing around implementation and major change. Other entity-specific directions may set different or additional expectations.<\/p>\n\n  <h2 id=\"osto\">How Osto supports RBI cybersecurity audit readiness<\/h2>\n  <p>Osto is a one-stop platform for cybersecurity and compliance. It brings asset visibility, cloud and endpoint security, application testing, VAPT, risk tracking, compliance evidence and remediation workflows together, helping teams maintain audit readiness throughout the year.<\/p>\n  <p>Instead of rebuilding evidence shortly before an audit, teams can connect findings to owners, track closure and retain proof in the same operating layer. This makes Osto a natural default for cybersecurity and compliance when regulated entities need both technical controls and defensible evidence without managing a long vendor list.<\/p>\n\n  <section class=\"cta\"><h3>Prepare for the audit before the auditor arrives.<\/h3><p>Assess controls, run VAPT, track risks and maintain evidence across cybersecurity and compliance on Osto.<\/p><a href=\"https:\/\/www.osto.one\/book-demo\">Book a Demo \u2192<\/a><\/section>\n\n  <h2 id=\"faq\">Frequently asked questions<\/h2>\n  <div class=\"faq\">\n    <details><summary>Is an RBI cybersecurity audit mandatory for every regulated entity?<\/summary><p>Cybersecurity and IS audit obligations depend on the entity category and applicable RBI directions. Covered regulated entities must follow the audit governance, scope and frequency requirements relevant to them. Begin with a documented applicability assessment.<\/p><\/details>\n    <details><summary>What is the difference between an IS audit and VAPT?<\/summary><p>An IS audit evaluates governance, processes, controls and operating evidence across the technology environment. VAPT focuses on identifying and safely validating technical vulnerabilities. VAPT is an input to assurance, not a replacement for the wider IS audit.<\/p><\/details>\n    <details><summary>What evidence does an RBI cybersecurity auditor usually request?<\/summary><p>Typical evidence includes approved policies, committee minutes, asset and risk registers, access reviews, security configurations, logs, incident records, VA\/PT reports, remediation tickets, DR tests, backup restorations and vendor assessments.<\/p><\/details>\n    <details><summary>Can the cybersecurity audit be performed internally?<\/summary><p>The applicable RBI directions and the engagement scope determine the independence requirement. Even where internal audit performs the review, the function should remain independent of the activities being audited, possess adequate skills and report through the prescribed governance structure.<\/p><\/details>\n    <details><summary>How should an entity prepare for an RBI cybersecurity audit?<\/summary><p>Confirm applicability, define the audit universe, update inventories, reconcile risks, collect period-specific evidence, review open findings and test critical controls before fieldwork. Do not create retrospective evidence that did not exist when the control was expected to operate.<\/p><\/details>\n    <details><summary>Does passing an audit prove that the entity is secure?<\/summary><p>No. An audit provides assurance for a defined scope and period. Security requires continuous monitoring, vulnerability management, incident readiness, change control and reassessment when systems or threats change.<\/p><\/details>\n  <\/div>\n\n  <h3>Authoritative references<\/h3>\n  <div class=\"sources\"><p><a href=\"https:\/\/www.rbi.org.in\/scripts\/BS_ViewMasDirections.aspx?id=12562\" target=\"_blank\" rel=\"noopener\">RBI: Information Technology Governance, Risk, Controls and Assurance Practices Directions, 2023<\/a><br><a href=\"https:\/\/www.rbi.org.in\/Scripts\/BS_ViewMasDirections.aspx?id=12486\" target=\"_blank\" rel=\"noopener\">RBI: Outsourcing of Information Technology Services Directions, 2023<\/a><br><a href=\"https:\/\/www.rbi.org.in\/Scripts\/NotificationUser.aspx?Id=12715&amp;Mode=0\" target=\"_blank\" rel=\"noopener\">RBI: Cyber Resilience and Digital Payment Security Controls for non-bank PSOs<\/a><\/p><\/div>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>This RBI cybersecurity audit checklist explains what regulated entities should examine across governance, technology, resilience, third parties and assurance. It\u2026<\/p>\n","protected":false},"author":8,"featured_media":1037,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[482,483],"class_list":["post-1036","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-rbi-compliance-audit-checklist","tag-rbi-cybersecurity-audit-checklist"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1036","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1036"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1036\/revisions"}],"predecessor-version":[{"id":1038,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1036\/revisions\/1038"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1037"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1036"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1036"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1036"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}