{"id":645,"date":"2026-08-13T06:04:46","date_gmt":"2026-08-13T06:04:46","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=645"},"modified":"2026-08-13T06:04:46","modified_gmt":"2026-08-13T06:04:46","slug":"cspm","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/cspm\/","title":{"rendered":"CSPM Explained: Cloud Security Posture Management"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: CSPM\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">CSPM continuously checks your cloud accounts against secure configuration baselines and flags the settings that would expose data or grant more access than intended.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Cloud<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>Cloud security posture management, or CSPM, connects to AWS, Azure or GCP, builds an inventory of what exists, compares each resource against secure baselines and compliance frameworks, and reports misconfigurations. It watches configuration rather than traffic, which is why it catches the exposure before anyone exploits it.<\/p>\n<\/div>\n\n<p>Cloud breaches usually start with a setting rather than an exploit: a storage bucket left public, a security group open to the internet, a role with far broader permissions than the workload needs.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#checks\">What CSPM checks<\/a><\/li>\n    <li><a href=\"#works\">How it works<\/a><\/li>\n    <li><a href=\"#others\">How it differs from other cloud tools<\/a><\/li>\n    <li><a href=\"#osto\">How Osto runs CSPM<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"checks\">What CSPM checks<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 240\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Five categories CSPM inspects: identity, storage, network, encryption and logging.\">\n  <text x=\"380\" y=\"26\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" letter-spacing=\"1.2\" fill=\"#0f1538\">WHAT GETS INSPECTED IN A CLOUD ACCOUNT<\/text>\n\n  <rect x=\"12\" y=\"44\" width=\"142\" height=\"112\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"83\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#4a52a8\">Identity<\/text>\n  <text x=\"83\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Over-permissive<\/text>\n  <text x=\"83\" y=\"114\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">roles, unused keys,<\/text>\n  <text x=\"83\" y=\"129\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">missing MFA<\/text>\n\n  <rect x=\"162\" y=\"44\" width=\"142\" height=\"112\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"233\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#3a6f5d\">Storage<\/text>\n  <text x=\"233\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Public buckets,<\/text>\n  <text x=\"233\" y=\"114\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">open snapshots,<\/text>\n  <text x=\"233\" y=\"129\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">weak policies<\/text>\n\n  <rect x=\"312\" y=\"44\" width=\"142\" height=\"112\" rx=\"14\" fill=\"#e2eff7\"\/>\n  <text x=\"383\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#2f6a89\">Network<\/text>\n  <text x=\"383\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Security groups<\/text>\n  <text x=\"383\" y=\"114\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">open to the world,<\/text>\n  <text x=\"383\" y=\"129\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">exposed databases<\/text>\n\n  <rect x=\"462\" y=\"44\" width=\"142\" height=\"112\" rx=\"14\" fill=\"#fbe9dc\"\/>\n  <text x=\"533\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#a2603a\">Encryption<\/text>\n  <text x=\"533\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Unencrypted disks<\/text>\n  <text x=\"533\" y=\"114\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">and databases,<\/text>\n  <text x=\"533\" y=\"129\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">key rotation gaps<\/text>\n\n  <rect x=\"612\" y=\"44\" width=\"136\" height=\"112\" rx=\"14\" fill=\"#f0e6f3\"\/>\n  <text x=\"680\" y=\"76\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"13.5\" font-weight=\"700\" fill=\"#6b4576\">Logging<\/text>\n  <text x=\"680\" y=\"99\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Audit trails off,<\/text>\n  <text x=\"680\" y=\"114\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">gaps in regions,<\/text>\n  <text x=\"680\" y=\"129\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">short retention<\/text>\n\n  <rect x=\"180\" y=\"180\" width=\"400\" height=\"40\" rx=\"12\" fill=\"#f4f5fd\"\/>\n  <text x=\"380\" y=\"205\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">All of it is configuration, none of it is traffic<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"works\" class=\"c-sage\">How it works<\/h2>\n\n<p>CSPM connects through read-only API access rather than agents. Once connected it inventories every resource, evaluates each against a rule set, and reports what fails. Because the cloud provider exposes configuration through an API, the check can run continuously instead of on a schedule.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Stage<\/th><th>What happens<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Connect<\/strong><\/td><td>Read-only role granted in each cloud account, across all regions<\/td><\/tr>\n    <tr><td><strong>Inventory<\/strong><\/td><td>Every resource discovered, including ones created outside your infrastructure code<\/td><\/tr>\n    <tr><td><strong>Evaluate<\/strong><\/td><td>Configuration compared against baselines such as CIS benchmarks and framework requirements<\/td><\/tr>\n    <tr><td><strong>Prioritise<\/strong><\/td><td>Findings ranked by exposure, for example public and holding data versus internal only<\/td><\/tr>\n    <tr><td><strong>Remediate<\/strong><\/td><td>Guided fix, and re-evaluation to confirm the setting actually changed<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">The drift problem it solves<\/p>\n  <p>Infrastructure code sets the intended state. Console changes made during an incident, a migration or a late release quietly diverge from it. CSPM sees the account as it actually is, not as the repository says it should be.<\/p>\n<\/div>\n\n<h2 id=\"others\" class=\"c-apri\">How it differs from other cloud tools<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Tool<\/th><th>Looks at<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>CSPM<\/strong><\/td><td>Configuration of cloud resources and accounts<\/td><\/tr>\n    <tr><td><strong>CWPP<\/strong><\/td><td>What is running inside workloads: hosts, containers, functions<\/td><\/tr>\n    <tr><td><strong>CIEM<\/strong><\/td><td>Cloud entitlements specifically, and who can reach what<\/td><\/tr>\n    <tr><td><strong><a href=\"https:\/\/www.osto.one\/resources\/glossary\/waf\/\">WAF<\/a><\/strong><\/td><td>Live traffic reaching the application, blocking attacks in flight<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto runs CSPM<\/h2>\n\n<p>Osto provides multi-cloud posture management across AWS, Azure and GCP, with continuous misconfiguration detection and evidence mapped to the compliance frameworks you are working towards. Because CSPM sits in the same platform as the WAF, endpoint control, IAM and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a>, a misconfiguration can be read next to what is actually happening on that resource, which is the difference between a finding and an incident.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Find the cloud setting that exposes your data<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Continuous posture management across AWS, Azure and GCP, with findings mapped to the frameworks you are working towards.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Multi-cloud &middot; Read-only access &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does CSPM stand for?<\/summary>\n  <p>Cloud security posture management. It refers to tools that continuously assess cloud account configuration against secure baselines and compliance requirements, and report the settings that create exposure.<\/p>\n<\/details>\n\n<details>\n  <summary>Is CSPM the same as a cloud vulnerability scan?<\/summary>\n  <p>No. A vulnerability scan looks for known software weaknesses. CSPM looks at configuration: permissions, exposure, encryption settings and logging. A fully patched environment can still be wide open because of a single misconfigured policy.<\/p>\n<\/details>\n\n<details>\n  <summary>Does CSPM need agents?<\/summary>\n  <p>No. It uses read-only API access to the cloud account. Workload protection tools that inspect processes inside a host or container do use agents, but posture management does not.<\/p>\n<\/details>\n\n<details>\n  <summary>Which frameworks expect CSPM?<\/summary>\n  <p>ISO 27001:2022 addresses cloud service security in <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A<\/a> 5.23 and configuration management in 8.9. SOC 2 auditors look for <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-evidence-collection\/\">evidence<\/a> that cloud configuration is monitored, and PCI DSS requires secure configuration standards under Requirement 2.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">SIEM<\/a> &middot; IAM &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest\/\">Encryption at Rest<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/ztna\/\">Zero Trust Network Access<\/a> &middot; CIS Benchmarks<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>CSPM continuously checks your cloud accounts against secure configuration baselines and flags the settings that would expose data or grant\u2026<\/p>\n","protected":false},"author":8,"featured_media":646,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[231,134,230],"class_list":["post-645","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-cloud-security-posture-management","tag-cspm","tag-multi-cloud-security"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/645","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=645"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/645\/revisions"}],"predecessor-version":[{"id":647,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/645\/revisions\/647"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/646"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=645"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=645"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=645"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}