{"id":657,"date":"2026-08-13T06:54:50","date_gmt":"2026-08-13T06:54:50","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=657"},"modified":"2026-08-13T06:54:50","modified_gmt":"2026-08-13T06:54:50","slug":"isms","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/isms\/","title":{"rendered":"ISMS Explained: The System ISO 27001 Certifies"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: ISMS\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">An ISMS is the set of policies, processes and records an organisation uses to manage information security decisions, rather than the security tools themselves.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Compliance<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>An information security management system, or ISMS, is a documented way of running security: what you protect, who owns each decision, how risks are assessed, and how you check the arrangement still works. <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> certifies the management system, not the individual tools.<\/p>\n<\/div>\n\n<p>The word &#8220;system&#8221; misleads people. An ISMS is not software you install. It is closer to how a finance function works: written rules, named owners, a regular review, and records proving the rules were followed.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#parts\">What an ISMS contains<\/a><\/li>\n    <li><a href=\"#cycle\">How it operates<\/a><\/li>\n    <li><a href=\"#scope\">Setting the scope<\/a><\/li>\n    <li><a href=\"#osto\">How Osto fits an ISMS<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"parts\">What an ISMS contains<\/h2>\n\n<p>Four things, and none of them is a product.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Scope and context<\/p>\n    <p>Which parts of the business, systems and locations are covered, and who the interested parties are.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Risk process<\/p>\n    <p>A repeatable method for identifying, analysing and treating information security risk, with named risk owners.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Controls and policies<\/p>\n    <p>The measures selected to treat those risks, and the written rules that govern them.<\/p>\n  <\/div>\n  <div class=\"tcard a\">\n    <p class=\"n\">Leadership commitment<\/p>\n    <p>An <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-policies-documentation\/\">approved policy<\/a>, allocated resources and defined responsibilities, signed off at the top.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Monitoring and audit<\/p>\n    <p>Internal audits, measurement of whether controls work, and a management review at a set interval.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Improvement<\/p>\n    <p>A process for handling nonconformities, recording corrective action and feeding it back into the system.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"cycle\" class=\"c-sage\">How it operates<\/h2>\n\n<p>An ISMS runs as a loop rather than a project. ISO 27001 does not name the Plan-Do-Check-Act cycle in the 2022 edition, but the clause structure still follows it, and auditors look for evidence that the loop turned at least once before certification.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 210\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"ISMS operating cycle: plan, do, check, act, repeating.\">\n  <defs><marker id=\"ismsA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker>\n  <marker id=\"ismsB\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"34\" width=\"166\" height=\"76\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"95\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">Plan<\/text>\n  <text x=\"95\" y=\"85\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Scope, risk criteria,<\/text>\n  <text x=\"95\" y=\"101\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">risk assessment<\/text>\n  <line x1=\"184\" y1=\"72\" x2=\"200\" y2=\"72\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#ismsA)\"\/>\n\n  <rect x=\"202\" y=\"34\" width=\"166\" height=\"76\" rx=\"14\" fill=\"#e3f0e9\"\/>\n  <text x=\"285\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#3a6f5d\">Do<\/text>\n  <text x=\"285\" y=\"85\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Implement controls<\/text>\n  <text x=\"285\" y=\"101\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">and policies<\/text>\n  <line x1=\"374\" y1=\"72\" x2=\"390\" y2=\"72\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#ismsA)\"\/>\n\n  <rect x=\"392\" y=\"34\" width=\"166\" height=\"76\" rx=\"14\" fill=\"#c2d9ec\"\/>\n  <text x=\"475\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#25547a\">Check<\/text>\n  <text x=\"475\" y=\"85\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">Internal audit and<\/text>\n  <text x=\"475\" y=\"101\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#0f1538\">management review<\/text>\n  <line x1=\"564\" y1=\"72\" x2=\"580\" y2=\"72\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#ismsA)\"\/>\n\n  <rect x=\"582\" y=\"34\" width=\"166\" height=\"76\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"665\" y=\"64\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">Act<\/text>\n  <text x=\"665\" y=\"85\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">Correct findings,<\/text>\n  <text x=\"665\" y=\"101\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11.5\" fill=\"#b9c1e6\">improve the system<\/text>\n\n  <path d=\"M665,118 L665,150 L95,150 L95,120\" fill=\"none\" stroke=\"#4a52a8\" stroke-width=\"2\" stroke-dasharray=\"6 5\" marker-end=\"url(#ismsB)\"\/>\n  <text x=\"380\" y=\"172\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">The cycle repeats. Certification checks that it has turned, not that security is finished.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"scope\" class=\"c-apri\">Setting the scope<\/h2>\n\n<p>Scope is the first decision and the one that shapes cost. A narrow scope certifies less but completes faster. An unrealistically narrow scope, such as excluding the product that customers actually buy, gets challenged by the certification body and by buyers reading the certificate.<\/p>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Scope element<\/th><th>What to state<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Products and services<\/strong><\/td><td>Which offerings are covered, named as customers would recognise them<\/td><\/tr>\n    <tr><td><strong>Locations<\/strong><\/td><td>Offices, data centres and cloud regions in scope, including remote working<\/td><\/tr>\n    <tr><td><strong>Systems<\/strong><\/td><td>The platforms, environments and supporting infrastructure included<\/td><\/tr>\n    <tr><td><strong>People<\/strong><\/td><td>Teams and functions bound by the ISMS policies<\/td><\/tr>\n    <tr><td><strong>Exclusions<\/strong><\/td><td>Anything left out, with a defensible reason<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto fits an ISMS<\/h2>\n\n<p>An ISMS decides what should be controlled; the controls themselves still have to exist. Osto supplies the technical half: access management, endpoint protection, logging, vulnerability testing and cloud posture, with evidence mapped to ISO 27001 and more than 200 other frameworks. The policies, risk decisions and management review remain yours, because they describe how your organisation makes decisions.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">The controls an ISMS asks you to prove<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto deploys the technical half of your management system and maps the evidence to ISO 27001 and 200+ frameworks.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Evidence from your own controls &middot; 200+ frameworks &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What does ISMS stand for?<\/summary>\n  <p>ISMS stands for information security management system. It is the documented set of policies, processes, responsibilities and records an organisation uses to manage information security risk.<\/p>\n<\/details>\n\n<details>\n  <summary>Is an ISMS the same as ISO 27001?<\/summary>\n  <p>No. ISO 27001 is the standard that specifies what an ISMS must contain. The ISMS is the thing your organisation builds and runs. You can operate an ISMS without ever seeking certification.<\/p>\n<\/details>\n\n<details>\n  <summary>Do we need software to run an ISMS?<\/summary>\n  <p>No. An ISMS is a set of documented processes and records. Compliance platforms make the evidence easier to collect and keep current, but the management system itself is organisational rather than technical.<\/p>\n<\/details>\n\n<details>\n  <summary>Who owns the ISMS?<\/summary>\n  <p>Leadership owns it under Clause 5, which requires an approved policy, allocated resources and assigned responsibilities. Day-to-day operation is usually delegated, but accountability cannot be.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-assessment\/\">Risk Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/risk-treatment-plan\/\">Risk Treatment Plan<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/annex-a-controls\/\">Annex A Controls<\/a> &middot; Internal Audit<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>An ISMS is the set of policies, processes and records an organisation uses to manage information security decisions, rather than\u2026<\/p>\n","protected":false},"author":8,"featured_media":658,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[237,236,238],"class_list":["post-657","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-information-security-management-system","tag-isms","tag-isms-scope"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/657","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=657"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/657\/revisions"}],"predecessor-version":[{"id":659,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/657\/revisions\/659"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/658"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=657"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=657"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=657"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}