{"id":724,"date":"2026-08-16T13:46:28","date_gmt":"2026-08-16T13:46:28","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=724"},"modified":"2026-08-16T13:46:28","modified_gmt":"2026-08-16T13:46:28","slug":"iso-27002","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/iso-27002\/","title":{"rendered":"What is ISO 27002 ?"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: ISO 27002\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">ISO 27002 is the guidance document that explains how to implement each of the controls listed in ISO 27001 Annex A. You cannot be certified against it.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">ISO 27001<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>ISO 27001 tells you which controls to consider. ISO 27002 tells you what each control means and how to implement it. Annex A of ISO 27001 lists the 93 controls in one line each; ISO 27002 devotes a page or more to every one of them. Certification is against ISO 27001 only. ISO 27002 is the reference book you keep open while doing the work.<\/p>\n<\/div>\n\n<p>Both were reissued in 2022 with the same restructure, so the control numbers in ISO 27002:2022 match Annex A exactly. If you are looking at a control reference like A.8.24, ISO 27002 has the corresponding section.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#difference\">ISO 27001 or ISO 27002?<\/a><\/li>\n    <li><a href=\"#inside\">What each control entry contains<\/a><\/li>\n    <li><a href=\"#attributes\">The five attributes<\/a><\/li>\n    <li><a href=\"#use\">How to actually use it<\/a><\/li>\n    <li><a href=\"#osto\">How Osto implements the controls<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"difference\">ISO 27001 or ISO 27002?<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 230\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"ISO 27001 is the certifiable requirements standard, ISO 27002 is the implementation guidance for its Annex A controls.\">\n  <defs><marker id=\"i2A\" markerWidth=\"9\" markerHeight=\"9\" refX=\"7\" refY=\"4.5\" orient=\"auto\"><path d=\"M0,0 L9,4.5 L0,9 z\" fill=\"#4a52a8\"\/><\/marker><\/defs>\n\n  <rect x=\"12\" y=\"34\" width=\"348\" height=\"164\" rx=\"18\" fill=\"#e9ecfa\"\/>\n  <text x=\"186\" y=\"68\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#4a52a8\">ISO 27001<\/text>\n  <text x=\"186\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">The requirements standard<\/text>\n  <rect x=\"36\" y=\"106\" width=\"300\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"186\" y=\"126\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Clauses 4 to 10, plus Annex A control list<\/text>\n  <rect x=\"36\" y=\"142\" width=\"300\" height=\"30\" rx=\"8\" fill=\"#1c267a\"\/>\n  <text x=\"186\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" font-weight=\"700\" fill=\"#ffffff\">You get certified against this<\/text>\n\n  <line x1=\"368\" y1=\"116\" x2=\"396\" y2=\"116\" stroke=\"#4a52a8\" stroke-width=\"2.5\" marker-end=\"url(#i2A)\"\/>\n  <text x=\"382\" y=\"104\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"10.5\" fill=\"#4a52a8\">refers to<\/text>\n\n  <rect x=\"404\" y=\"34\" width=\"344\" height=\"164\" rx=\"18\" fill=\"#e3f0e9\"\/>\n  <text x=\"576\" y=\"68\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#3a6f5d\">ISO 27002<\/text>\n  <text x=\"576\" y=\"92\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">The implementation guidance<\/text>\n  <rect x=\"428\" y=\"106\" width=\"296\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"576\" y=\"126\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">A full explanation of all 93 controls<\/text>\n  <rect x=\"428\" y=\"142\" width=\"296\" height=\"30\" rx=\"8\" fill=\"#ffffff\"\/>\n  <text x=\"576\" y=\"162\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Guidance only, no certification<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Certificates say ISO 27001. Nobody issues an ISO 27002 certificate.<\/figcaption>\n<\/figure>\n\n<p>The practical relationship: <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001\/\">ISO 27001<\/a> is what your auditor tests you against, and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001-annex-a-controls\/\">Annex A<\/a> is the shortlist inside it. When a one-line control title is not enough to know what to build, ISO 27002 is where you look next.<\/p>\n\n<h2 id=\"inside\" class=\"c-sage\">What each control entry contains<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Section<\/th><th>What it gives you<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Control<\/strong><\/td><td>The same one-line statement that appears in Annex A<\/td><\/tr>\n    <tr><td><strong>Purpose<\/strong><\/td><td>Why the control exists and what risk it addresses<\/td><\/tr>\n    <tr><td><strong>Guidance<\/strong><\/td><td>The substance: what implementing it involves, often across several pages<\/td><\/tr>\n    <tr><td><strong>Other information<\/strong><\/td><td>Context, related standards and edge cases worth knowing<\/td><\/tr>\n    <tr><td><strong>Attributes<\/strong><\/td><td>Five tags that let you filter and group controls in other ways<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<div class=\"callout\">\n  <p class=\"k\">Guidance, not a checklist<\/p>\n  <p>ISO 27002 says what to consider, not what you must do. An auditor will not fail you for departing from its guidance, provided your <a href=\"https:\/\/www.osto.one\/resources\/glossary\/information-security-risk-assessment\/\">risk assessment<\/a> supports the choice you made. What they will question is a control you claimed as applicable but never implemented, which is the same trap teams hit with <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-controls-cc1-cc9\/\" target=\"_blank\" rel=\"noopener\">SOC 2 controls<\/a>.<\/p>\n<\/div>\n\n<h2 id=\"attributes\" class=\"c-apri\">The five attributes<\/h2>\n\n<p>New in the 2022 edition. Each control carries five tags, so the same 93 controls can be viewed through whichever lens suits the audience.<\/p>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Attribute<\/th><th>Example values<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>Control type<\/strong><\/td><td>Preventive, detective, corrective<\/td><\/tr>\n    <tr><td><strong>Information security properties<\/strong><\/td><td>Confidentiality, integrity, availability<\/td><\/tr>\n    <tr><td><strong>Cybersecurity concepts<\/strong><\/td><td>Identify, protect, detect, respond, recover<\/td><\/tr>\n    <tr><td><strong>Operational capabilities<\/strong><\/td><td>Identity and access management, application security, threat management<\/td><\/tr>\n    <tr><td><strong>Security domains<\/strong><\/td><td>Governance and ecosystem, protection, defence, resilience<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>They are optional. Nothing in ISO 27001 requires you to use attributes, and no auditor will ask for them. They are useful mainly when you need to show coverage to a technical audience rather than a compliance one.<\/p>\n\n<h2 id=\"use\" class=\"c-plum\">How to actually use it<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Start from the risk<\/p>\n    <p>Assess risk first, decide which controls apply, then open ISO 27002 for the ones you kept.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Read the purpose line<\/p>\n    <p>When you cannot tell what a control is for, the purpose statement resolves it faster than the guidance does.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Write your own procedure<\/p>\n    <p>Do not paste the guidance into a policy. Auditors test what you actually do, not what the standard says.<\/p>\n  <\/div>\n<\/div>\n\n<h2 id=\"osto\">How Osto implements the controls<\/h2>\n\n<p>Most Annex A controls in the technological theme need a tool behind them, not a document. Osto deploys those directly: access control and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/encryption-at-rest-and-in-transit\/\">encryption<\/a>, logging and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">monitoring<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">vulnerability testing<\/a>, endpoint control and secure development testing. The platform maps each one to its Annex A reference and collects the evidence as the control runs, so your <a href=\"https:\/\/www.osto.one\/resources\/glossary\/statement-of-applicability\/\">Statement of Applicability<\/a> reflects what is genuinely in place.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Controls that run, not controls on paper<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Osto deploys the technical controls behind Annex A and maps the evidence to each reference, so implementation and documentation stay in step.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">200+ frameworks &middot; Evidence from live controls &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is ISO 27002?<\/summary>\n  <p>ISO 27002 is the implementation guidance standard for information security controls. It explains, in detail, each of the 93 controls listed in Annex A of ISO 27001. It is a reference document, not a certifiable standard.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between ISO 27001 and ISO 27002?<\/summary>\n  <p>ISO 27001 contains the requirements for a management system and lists controls in Annex A, and it is what you get certified against. ISO 27002 explains how to implement each of those controls and offers no certification.<\/p>\n<\/details>\n\n<details>\n  <summary>Can you be certified to ISO 27002?<\/summary>\n  <p>No. There is no ISO 27002 certification. Any claim of being ISO 27002 certified is a misunderstanding. Certification is issued against ISO 27001 by an accredited certification body.<\/p>\n<\/details>\n\n<details>\n  <summary>Do you have to follow ISO 27002 guidance exactly?<\/summary>\n  <p>No. It is guidance rather than requirement. You can implement a control differently if your risk assessment justifies the approach. What you cannot do is mark a control applicable and then not implement it in any form.<\/p>\n<\/details>\n\n<details>\n  <summary>Do the ISO 27002:2022 control numbers match Annex A?<\/summary>\n  <p>Yes. Both were revised in 2022 using the same structure of four themes and 93 controls, so a reference such as A.8.24 in Annex A corresponds directly to section 8.24 in ISO 27002.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> ISO 27001 &middot; Annex A Controls &middot; ISMS &middot; Statement of Applicability &middot; Risk Assessment &middot; Certification Body<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>ISO 27002 is the guidance document that explains how to implement each of the controls listed in ISO 27001 Annex\u2026<\/p>\n","protected":false},"author":8,"featured_media":725,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[278],"class_list":["post-724","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-iso-27002"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=724"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/724\/revisions"}],"predecessor-version":[{"id":726,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/724\/revisions\/726"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/725"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}