{"id":733,"date":"2026-08-16T14:28:33","date_gmt":"2026-08-16T14:28:33","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=733"},"modified":"2026-08-16T14:28:33","modified_gmt":"2026-08-16T14:28:33","slug":"iso-27001-internal-audit","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/iso-27001-internal-audit\/","title":{"rendered":"Internal Audit"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: INTERNAL AUDIT\n     Shared glossary design system. Paste into one Custom HTML block. No H1.\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">An internal audit is the check you run on your own management system, before an external auditor runs theirs. ISO 27001 clause 9.2 requires it.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">ISO 27001<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>An internal audit tests whether your controls and processes are being followed in practice, using the same evidence-sampling approach an external auditor would use. It must be planned, objective and documented, and the person auditing cannot audit their own work. You need at least one completed internal audit before Stage 1, and a continuing programme after certification.<\/p>\n<\/div>\n\n<p>The one thing that makes it useless: treating it as a form-filling exercise. An internal audit that finds nothing is either a perfect organisation or, far more likely, an audit that did not look.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#requires\">What clause 9.2 requires<\/a><\/li>\n    <li><a href=\"#process\">How an internal audit runs<\/a><\/li>\n    <li><a href=\"#who\">Who can perform it<\/a><\/li>\n    <li><a href=\"#mistakes\">Mistakes that become findings<\/a><\/li>\n    <li><a href=\"#osto\">How Osto supports the programme<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"requires\">What clause 9.2 requires<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Requirement<\/th><th>What it means in practice<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Planned intervals<\/td><td>A programme with dates, not an audit done whenever someone remembers<\/td><\/tr>\n    <tr><td>Defined criteria and scope<\/td><td>Each audit states what it is testing against and which areas it covers<\/td><\/tr>\n    <tr><td>Objectivity and impartiality<\/td><td>Auditors do not audit work they are responsible for<\/td><\/tr>\n    <tr><td>Results reported to management<\/td><td>Findings go to the people who can act on them, and into the management review<\/td><\/tr>\n    <tr><td>Documented evidence<\/td><td>The programme, the plan, the findings and the corrective actions are all retained<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<p>Coverage is judged across the programme, not per audit. You can audit access control in March and supplier management in July, provided the plan shows the whole <a href=\"https:\/\/www.osto.one\/resources\/glossary\/isms\/\">ISMS<\/a> gets covered over the cycle.<\/p>\n\n<h2 id=\"process\" class=\"c-sage\">How an internal audit runs<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 180\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"Internal audit cycle: plan, gather evidence, report findings, agree corrective action, then verify closure.\">\n  <defs><marker id=\"iaA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n\n  <rect x=\"8\" y=\"40\" width=\"132\" height=\"80\" rx=\"13\" fill=\"#e9ecfa\"\/>\n  <text x=\"74\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#4a52a8\">1. Plan<\/text>\n  <text x=\"74\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Scope, criteria,<\/text>\n  <text x=\"74\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">dates, auditor<\/text>\n  <line x1=\"146\" y1=\"80\" x2=\"158\" y2=\"80\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#iaA)\"\/>\n\n  <rect x=\"164\" y=\"40\" width=\"132\" height=\"80\" rx=\"13\" fill=\"#e3f0e9\"\/>\n  <text x=\"230\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#3a6f5d\">2. Gather<\/text>\n  <text x=\"230\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Sample records,<\/text>\n  <text x=\"230\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">interview people<\/text>\n  <line x1=\"302\" y1=\"80\" x2=\"314\" y2=\"80\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#iaA)\"\/>\n\n  <rect x=\"320\" y=\"40\" width=\"132\" height=\"80\" rx=\"13\" fill=\"#fbe9dc\"\/>\n  <text x=\"386\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#a2603a\">3. Report<\/text>\n  <text x=\"386\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Findings graded<\/text>\n  <text x=\"386\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">and evidenced<\/text>\n  <line x1=\"458\" y1=\"80\" x2=\"470\" y2=\"80\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#iaA)\"\/>\n\n  <rect x=\"476\" y=\"40\" width=\"132\" height=\"80\" rx=\"13\" fill=\"#f0e6f3\"\/>\n  <text x=\"542\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#6b4576\">4. Correct<\/text>\n  <text x=\"542\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">Root cause and<\/text>\n  <text x=\"542\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#0f1538\">owner assigned<\/text>\n  <line x1=\"614\" y1=\"80\" x2=\"626\" y2=\"80\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#iaA)\"\/>\n\n  <rect x=\"632\" y=\"40\" width=\"120\" height=\"80\" rx=\"13\" fill=\"#1c267a\"\/>\n  <text x=\"692\" y=\"70\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" font-weight=\"700\" fill=\"#ffffff\">5. Verify<\/text>\n  <text x=\"692\" y=\"91\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">Closed with<\/text>\n  <text x=\"692\" y=\"106\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"11\" fill=\"#b9c1e6\">proof, not a tick<\/text>\n\n  <text x=\"380\" y=\"156\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Step 5 is the one most often skipped, and the one external auditors check hardest.<\/text>\n<\/svg>\n<\/div>\n<\/figure>\n\n<h2 id=\"who\" class=\"c-apri\">Who can perform it<\/h2>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Someone internal<\/p>\n    <p>Any competent employee, as long as they are independent of the area being audited. No formal qualification is required.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Cross-cover in a small team<\/p>\n    <p>Engineering audits HR processes, HR audits engineering. Objectivity comes from separation, not seniority.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">An external consultant<\/p>\n    <p>Allowed, and common. It stays an internal audit because it is your programme. It cannot be your certification body.<\/p>\n  <\/div>\n<\/div>\n\n<div class=\"callout\">\n  <p class=\"k\">Independence is the hard rule<\/p>\n  <p>The person who set up your access reviews cannot audit access reviews. In a ten-person company that takes planning, but it is not optional and an external auditor will ask who performed each audit.<\/p>\n<\/div>\n\n<h2 id=\"mistakes\" class=\"c-plum\">Mistakes that become findings<\/h2>\n\n<table class=\"h-peri\">\n  <thead>\n    <tr><th>Mistake<\/th><th>Why it fails<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>No findings at all<\/td><td>Reads as an audit that did not test anything, not as a clean system<\/td><\/tr>\n    <tr><td>Findings raised but never closed<\/td><td>Directly contradicts clause 10, and is trivially easy to spot<\/td><\/tr>\n    <tr><td>The ISMS owner audits their own ISMS<\/td><td>Breaches the impartiality requirement in clause 9.2<\/td><\/tr>\n    <tr><td>A checklist with no evidence attached<\/td><td>Nothing shows records were actually sampled, unlike proper <a href=\"https:\/\/osto.one\/resources\/blog\/soc-2-evidence-collection\/\" target=\"_blank\" rel=\"noopener\">evidence collection<\/a><\/td><\/tr>\n    <tr><td>Results never reach management review<\/td><td>Breaks the required link between clause 9.2 and clause 9.3<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"osto\">How Osto supports the programme<\/h2>\n\n<p>An internal audit is only as easy as the evidence behind it. Osto keeps that evidence live: access and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/mfa\/\">MFA<\/a> records, endpoint state, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/cspm\/\">cloud configuration<\/a>, <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vapt\/\">testing<\/a> results and <a href=\"https:\/\/www.osto.one\/resources\/glossary\/siem\/\">log data<\/a>, all mapped to the relevant <a href=\"https:\/\/www.osto.one\/resources\/glossary\/iso-27001-annex-a-controls\/\">Annex A<\/a> controls. Your internal auditor samples from the platform instead of chasing screenshots, and the gaps they find are the real ones rather than gaps in record keeping.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Give your internal auditor something real to sample<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Access records, endpoint state, cloud posture and test results, all mapped to Annex A and available without chasing screenshots.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Evidence in one place &middot; Annex A mapped &middot; One platform, everything<\/p>\n<\/div>\n\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is an internal audit in ISO 27001?<\/summary>\n  <p>A planned, documented review of your own information security management system, testing whether controls and processes are being followed. Clause 9.2 requires it, and results feed the management review.<\/p>\n<\/details>\n\n<details>\n  <summary>How often must an internal audit be done?<\/summary>\n  <p>ISO 27001 says planned intervals rather than a fixed frequency. Most organisations run an annual programme that covers the whole ISMS across the year, sometimes split into several smaller audits.<\/p>\n<\/details>\n\n<details>\n  <summary>Who can perform an internal audit?<\/summary>\n  <p>Any competent person who is independent of the area being audited. No certification is required. Small teams often cross-cover between functions, or bring in an external consultant, who cannot be the certification body.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between internal and external audit?<\/summary>\n  <p>An internal audit is your own check, run by you or on your behalf, and produces no certificate. An external audit is conducted by an accredited certification body and determines whether certification is granted or maintained.<\/p>\n<\/details>\n\n<details>\n  <summary>Do you need an internal audit before certification?<\/summary>\n  <p>Yes. At least one full internal audit and one management review must be complete before Stage 1. Arriving without them is one of the most common reasons a certification audit is delayed.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> ISO 27001 &middot; ISMS &middot; Stage 1 and Stage 2 Audit &middot; Surveillance Audit &middot; Certification Body &middot; Risk Assessment<\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>An internal audit is the check you run on your own management system, before an external auditor runs theirs. ISO\u2026<\/p>\n","protected":false},"author":8,"featured_media":734,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[282],"class_list":["post-733","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-internal-audit"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/733","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=733"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/733\/revisions"}],"predecessor-version":[{"id":735,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/733\/revisions\/735"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/734"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=733"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=733"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=733"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}