{"id":62441,"date":"2021-03-22T23:15:57","date_gmt":"2021-03-22T22:15:57","guid":{"rendered":"https:\/\/blog.wedos.cz\/?p=62441"},"modified":"2021-03-29T22:52:59","modified_gmt":"2021-03-29T20:52:59","slug":"ziskali-jsme-dve-dulezite-cloudove-certifikace-iso-27017-a-iso-27018","status":"publish","type":"post","link":"https:\/\/blog.wedos.com\/cs\/ziskali-jsme-dve-dulezite-cloudove-certifikace-iso-27017-a-iso-27018","title":{"rendered":"Z\u00edskali jsme dv\u011b d\u016fle\u017eit\u00e9 cloudov\u00e9 certifikace ISO 27017  a ISO 27018"},"content":{"rendered":"<p>Na spu\u0161t\u011bn\u00ed slu\u017eby <a href=\"https:\/\/www.wedos.cz\/cloud\" target=\"_blank\" rel=\"noopener\">WEDOS Cloud<\/a> jsme se dlouhou dobu p\u0159ipravovali. Prob\u00edhal nejen v\u00fdvoj software a rozs\u00e1hl\u00e9 testov\u00e1n\u00ed hardware, ale tak\u00e9 jsme se v\u011bnovali ot\u00e1zk\u00e1m pr\u00e1vn\u00edm, bezpe\u010dnostn\u00edm a jak to v\u0161e zakomponovat do sou\u010dasn\u00e9ho sv\u011bta.<\/p>\n<p>Kdy\u017e u\u017e jsme tomu v\u011bnovali tolik \u010dasu, tak n\u00e1s napadlo, \u017ee by st\u00e1lo za to m\u00edt i n\u011bjak\u00e9 nez\u00e1visl\u00e9 potvrzen\u00ed, a tak jsme za\u010dali pracovat na z\u00edsk\u00e1n\u00ed certifikac\u00ed ISO 27017 a ISO 27018, kter\u00e9 jsem 16.03.2021 \u00fasp\u011b\u0161n\u011b z\u00edskali.<\/p>\n<p><!--more--><\/p>\n<h3>Bezpe\u010dnost dat je obchodn\u00ed i politickou&nbsp; prioritou<\/h3>\n<p>\u017dijeme v \u010cesk\u00e9 Republice, kter\u00e1 je sou\u010d\u00e1st\u00ed Evropsk\u00e9 Unie a tlak na bezpe\u010dnost a ochranu osobn\u00edch \u00fadaj\u016f je zde velk\u00fd. Na\u0161\u00edm c\u00edlem je nab\u00eddnout v\u00e1m takov\u00e9 slu\u017eby, u kter\u00fdch si s t\u011bmito ot\u00e1zkami nebudete muset d\u011blat starosti dnes ani v n\u00e1sleduj\u00edc\u00edch letech, kdy n\u00e1roky na ochranu osobn\u00edch \u00fadaj\u016f budou d\u00e1le stoupat.<\/p>\n<p>Mnoho na\u0161ich konkurent\u016f se nap\u0159\u00edklad ke GDPR postavilo zna\u010dn\u011b laxn\u011b. My jsme se <a href=\"https:\/\/datacentrum.wedos.com\/a\/387\/vase-nejcastejsi-otazky-k-gdpr.html\" target=\"_blank\" rel=\"noopener\">t\u00e9matu GDPR u\u017e od za\u010d\u00e1tku v\u011bnovali opravdu intenzivn\u011b<\/a> a konzultovali v\u0161e s \u00fa\u0159ady a pr\u00e1vn\u00edky. V\u00fdsledkem pro z\u00e1kazn\u00edka je nap\u0159\u00edklad evidence zpracovatelsk\u00fdch smluv ke ka\u017ed\u00e9 jednotliv\u00e9 slu\u017eb\u011b, v\u010detn\u011b v\u0161ech reviz\u00ed, kter\u00e9 si mohou z\u00e1kazn\u00edci st\u00e1hnout. Syst\u00e9m a texty byly od spu\u0161t\u011bn\u00ed upravov\u00e1ny tak, aby odpov\u00eddaly po\u017eadavk\u016fm nejen u n\u00e1s, ale i v zahrani\u010d\u00ed. To je tak\u00e9 jeden z d\u016fvod\u016f, pro\u010d jsou dokumenty pro GDPR prozat\u00edm pouze v \u010de\u0161tin\u011b.<\/p>\n<p>GDPR je ale jen \u0161pi\u010dka ledovce, kter\u00e1 rozv\u00ed\u0159ila t\u00e9ma ochrany osobn\u00edch \u00fadaj\u016f a p\u0159ipravenost firem na r\u016fzn\u00e1 bezpe\u010dnostn\u00ed a pr\u00e1vn\u00ed \u00faskal\u00ed. Mnoho z\u00e1kazn\u00edk\u016f ne\u017e si n\u00e1s vybere, tak sleduje, zdali dodr\u017eujeme to, co n\u00e1m na\u0159izuje z\u00e1kon (nap\u0159\u00edklad v\u0161echny listiny publikujeme na jutice.cz), hledaj\u00ed re\u00e1ln\u00e9 reference anebo zdali u n\u00e1s prob\u00edhaj\u00ed r\u016fzn\u00e9 audity. Zat\u00edm jsme v\u0161\u00edm \u00fasp\u011b\u0161n\u011b pro\u0161li a z\u00edskali hodn\u011b zku\u0161enost\u00ed, co z\u00e1kazn\u00edci cht\u011bj\u00ed. I kdy\u017e n\u011bkdy mus\u00edme t\u0159eba vysv\u011btlovat, jak tak &#8222;mal\u00e1&#8220; firma s m\u00e9n\u011b jak 50 zam\u011bstnanci, dok\u00e1\u017ee b\u00fdt dlouhodob\u011b jedni\u010dkou na \u010desk\u00e9m trhu.<\/p>\n<p>GDPR bylo hodn\u011b o firemn\u00edch procesech a postupech. Z na\u0161\u00ed strany jsme toho moc m\u011bnit nemuseli a to d\u00edky p\u0159\u00edsn\u00fdm podm\u00ednk\u00e1m, kter\u00e9 jsme si nastavili podle mezin\u00e1rodn\u00edch norem ISO 9001 (syst\u00e9m managementu kvality), ISO 14001 (syst\u00e9m environment\u00e1ln\u00edho managementu) a zejm\u00e9na ISO 27001 (syst\u00e9m managementu bezpe\u010dnosti informac\u00ed).<\/p>\n<p>ISO certifikace dr\u017e\u00edme a obnovujeme od roku 2011 (resp. 2013 pro ISO 27001), hlavn\u011b kv\u016fli z\u00e1kazn\u00edk\u016fm. Jsou z\u00e1rukou, \u017ee to co p\u00ed\u0161eme, nejsou jen pr\u00e1zdn\u00e1 slova, ale opravdu db\u00e1me na kvalitu a bezpe\u010dnost slu\u017eeb. V\u0161e je zaru\u010deno nez\u00e1visl\u00fdm auditem, kter\u00fd prob\u00edh\u00e1 ka\u017ed\u00fd rok jako dozorov\u00fd audit &nbsp;a jednou za 3 roky pak rozs\u00e1hlej\u0161\u00ed recertifikace.&nbsp;\u017de m\u00e1me v\u0161e v po\u0159\u00e1dku a jsme zdrav\u00e1 spole\u010dnost dok\u00e1zal i n\u00e1ro\u010dn\u00fd <a href=\"https:\/\/blog.wedos.cz\/wedos-ziskal-akreditaci-icann-pro-registraci-domen-a-hodlame-ji-vyuzit-naplno\" target=\"_blank\" rel=\"noopener\">akredita\u010dn\u00ed proces ICANN<\/a>.<\/p>\n<p>V\u011bt\u0161in\u011b z\u00e1kazn\u00edk\u016f tohle, spole\u010dn\u011b s re\u00e1ln\u00fdmi fotkami na\u0161ich datacenter, kancel\u00e1\u0159\u00ed a hardware sta\u010d\u00ed. Nicm\u00e9n\u011b u slu\u017eby WEDOS Cloud jsme opakovan\u011b narazili na po\u017eadavek ISO 27017 &#8211; Kontrola zabezpe\u010den\u00ed cloudov\u00fdch slu\u017eeb.<\/p>\n<h3>ISO 27017 &#8211; Kontrola zabezpe\u010den\u00ed cloudov\u00fdch slu\u017eeb<\/h3>\n<p>ISO\/IEC 27017 je relativn\u011b nov\u00fd n\u00e1rodn\u00ed standard, kter\u00fd byl p\u0159ijat v prosinci 2015. Cel\u00fd n\u00e1zev je<em> Code of practice for information security controls based on ISO\/IEC 27002 for cloud services<\/em> neboli <em>Kodex praxe pro \u0159\u00edzen\u00ed bezpe\u010dnosti informac\u00ed odvozen\u00fd od ISO\/IEC 27002 pro cloudov\u00e9 slu\u017eby<\/em>.<\/p>\n<p>Roz\u0161i\u0159uje tedy ISO 27002 a implementuje pokyny vztahuj\u00edc\u00ed se konkretn\u011b ke cloudov\u00fdm slu\u017eb\u00e1m a z\u00e1kazn\u00edk\u016fm t\u011bchto slu\u017eeb. ISO 27002 je ur\u010deno pro provozovatele, kte\u0159\u00ed se staraj\u00ed o z\u00e1zem\u00ed (hardware, software, podpora) pro zpracov\u00e1n\u00ed dat.<\/p>\n<p>My jsme zvolili ISO 27001, proto\u017ee pro provoz slu\u017eeb jako je n\u00e1\u0161 sd\u00edlen\u00fd webhosting NoLimit, WMS, mailservery anebo i evidenci kontakt\u016f v administraci je pro n\u00e1s ide\u00e1ln\u00ed ISO 27001, proto\u017ee zde p\u0159ich\u00e1z\u00edme do kontaktu s daty z\u00e1kazn\u00edk\u016f a mus\u00edme se postarat o jejich bezpe\u010dn\u00fd provoz.<\/p>\n<h4>Co obn\u00e1\u0161\u00ed ISO 27017 oproti ISO 27001 nav\u00edc<\/h4>\n<p>Do na\u0161ich intern\u00edch proces\u016f jsme museli zapracovat konkr\u00e9tn\u00ed postupy a odpov\u011bdn\u00e9 osoby pro:<\/p>\n<ul>\n<li>Sd\u00edlen\u00ed rol\u00ed a odpov\u011bdnost\u00ed v prost\u0159ed\u00ed cloudu (Vztah mezi z\u00e1kazn\u00edkem a poskytovatelem).\n<ul>\n<li><em>Tato \u010d\u00e1st se t\u00fdk\u00e1 hlavn\u011b smluvn\u00edch podm\u00ednek (pr\u00e1vn\u00ed vztahy, GDPR), ale je dobr\u00e9 v tom m\u00edt jasno<br \/>\n<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Zajistit bezprobl\u00e9mov\u00e9 a bezpe\u010dn\u00e9 odstra\u0148ov\u00e1n\u00ed v\u0161ech dat z cloudu.\n<ul>\n<li><em>Mus\u00ed se stanovit jasn\u00e1 pravidla maz\u00e1n\u00ed aktivn\u00edch dat, z\u00e1loh a dohled nad t\u00edm, \u017ee jsou opravdu smaz\u00e1na. To u\u017e jsme m\u011bli kv\u016fli GDRP obecn\u011b. Pro cloud je to v\u00edce konkr\u00e9tn\u00ed.<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Spr\u00e1vn\u00e9 a bezpe\u010dn\u00e9 odd\u011blen\u00ed z\u00e1kaznick\u00fdch slu\u017eeb ve virtu\u00e1ln\u00edm prost\u0159ed\u00ed\n<ul>\n<li><em>Slu\u017ebu WEDOS Cloud chceme p\u0159ipravit i na mo\u017enost provozovat jako priv\u00e1tn\u00ed cloud (na vyhrazen\u00e9m hardware).<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Pos\u00edlen\u00ed bezpe\u010dnosti vytvo\u0159en\u00fdch virtu\u00e1ln\u00edch stoj\u016f (VM).\n<ul>\n<li><em>Tato \u010d\u00e1st je hlavn\u011b o anal\u00fdze potenci\u00e1ln\u00edch hrozeb, navr\u017een\u00ed vhodn\u00e9ho monitoringu, p\u0159\u00edpadn\u011b zapojen\u00ed dal\u0161\u00edch bezpe\u010dnostn\u00edch prvk\u016f nad \u00farovn\u00ed cloudu do cel\u00e9ho procesu (DDoS ochrana, IPS\/IDS ochrana, SYN filtr, Geoblokace atd.)<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Zabezpe\u010den\u00ed administra\u010dn\u00ed \u010dinnosti.\n<ul>\n<li><em>Nebezpe\u010d\u00ed ne\u010d\u00edh\u00e1 jen v samotn\u00e9 slu\u017eb\u011b cloudu, ale i v\u0161ech slu\u017eb\u00e1ch, kter\u00e9 umo\u017e\u0148uj\u00ed z\u00e1kazn\u00edkovi jejich pohodlnou spr\u00e1vu.<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Monitorov\u00e1n\u00ed cloudov\u00fdch slu\u017eeb.\n<ul>\n<li><em>WEDOS Cloud je velice komplexn\u00ed slu\u017eba skl\u00e1daj\u00edc\u00ed se z mnoha \u010d\u00e1st\u00ed. V\u0161e se mus\u00ed sledovat (monitoring, logy, monitorov\u00e1n\u00ed, \u017ee funguje monitorov\u00e1n\u00ed) a vyhodnocovat (pravideln\u011b i n\u00e1hodn\u011b).<\/em><\/li>\n<li><em>K r\u016fzn\u00fdm \u010d\u00e1stem maj\u00ed p\u0159\u00edstup kolegov\u00e9 podle sv\u00e9 odbornosti, prov\u011b\u0159en\u00ed a pracovn\u00ed n\u00e1pln\u011b. Mus\u00ed b\u00fdt zaji\u0161t\u011bno, \u017ee v\u017edy bude k dispozici n\u011bkdo, kdo dok\u00e1\u017ee z\u00edskat pot\u0159ebn\u00e9 informace k \u0159e\u0161en\u00ed probl\u00e9mu.<\/em><\/li>\n<\/ul>\n<\/li>\n<li>Zaji\u0161t\u011bn\u00ed spr\u00e1vy zabezpe\u010den\u00ed pro fyzick\u00e9 i virtu\u00e1ln\u00ed s\u00ed\u0165\u011b.\n<ul>\n<li><em>Hlavn\u011b se jedn\u00e1 op\u011bt o monitorov\u00e1n\u00ed a odpov\u011bdn\u00e9 osoby.<\/em><\/li>\n<li><em>Tady m\u00e1me velkou v\u00fdhodu, proto\u017ee fyzickou s\u00ed\u0165 m\u00e1me kompletn\u011b pod na\u0161\u00ed spr\u00e1vou. Je v na\u0161ich priv\u00e1tn\u00edch datacentrech, nikdo ciz\u00ed k n\u00ed nem\u00e1 p\u0159\u00edstup. Dokonce ob\u011b optick\u00e9 trasy DC1 &lt;-&gt; DC2 jsou na\u0161e (sami jsme si je vykopali, nat\u00e1hli chr\u00e1ni\u010dky, zafukovali). V\u00edme v\u0161e o ka\u017ed\u00e9m metru.<\/em><\/li>\n<li><em>Intern\u00ed komunikace mezi jednotliv\u00fdmi VM nep\u016fjde p\u0159es hardware nikoho t\u0159et\u00edho.<\/em><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Tohle je jen zlomek v\u011bc\u00ed, kter\u00e9 mus\u00edme zapracovat do ofici\u00e1ln\u00edch postup\u016f. Ze samotn\u00e9 27001 vypl\u00fdvaj\u00ed des\u00edtky dal\u0161\u00edch proces\u016f.<\/p>\n<h3>ISO 27018 &#8211; Ochrana osobn\u00edch informac\u00ed&nbsp; ve ve\u0159ejn\u00fdch cloudech<\/h3>\n<p>ISO\/IEC 27018 je v\u016fbec prvn\u00ed mezin\u00e1rodn\u00ed standard zam\u011b\u0159en\u00fd na ochranu osobn\u00edch \u00fadaj\u016f v cloudu. Byl vytvo\u0159en v roce 2014 jako roz\u0161\u00ed\u0159en\u00ed ISO 27001 a m\u00e1 za c\u00edl pomoci poskytovatel\u016fm cloudov\u00fdch slu\u017eeb, kte\u0159\u00ed zpracov\u00e1vaj\u00ed data osobn\u00edho charakteru, posoudit rizika a zav\u00e9st dostate\u010dn\u00e9 kontroln\u00ed mechanizmy.&nbsp; Je tedy ur\u010den hlavn\u011b pro provozovatele slu\u017eeb typu SaaS (Software jako slu\u017eba).<\/p>\n<p>ISO 27018 vzniklo spojen\u00edm n\u011bkolika zn\u00e1m\u00fdch a autoritativn\u00edch standard\u016f &#8211; HIPAA (obs\u00e1hl osobn\u00ed zdravotnick\u00e9 informace), SSAE a ISAE (co\u017e jsou auditovan\u00e9 standarty pro&nbsp; bezpe\u010dnostn\u00ed \u0159\u00edzen\u00ed a \u00fa\u010dinnost bezpe\u010dnostn\u00edch kontrol stanoven\u00e9<em> Americk\u00fdm institutem certifikovan\u00fdch ve\u0159ejn\u00fdch \u00fa\u010detn\u00edch<\/em> (AICPA) a <em>Radou pro mezin\u00e1rodn\u00ed auditorsk\u00e9 a ov\u011b\u0159ovac\u00ed standardy mezin\u00e1rodn\u00ed federace \u00fa\u010detn\u00edch <\/em>(IAASB)).<\/p>\n<p>Tento standard m\u00e1 dv\u011b verze ISO\/IEC 27018:2014 a ISO\/IEC 27018:2019. My jsme certifikov\u00e1n\u00ed podle nov\u011bj\u0161\u00ed ISO\/IEC 27018:2019.<\/p>\n<p>Co ISO 27018 vypov\u00edd\u00e1 o na\u0161ich slu\u017eb\u00e1ch:<\/p>\n<ul>\n<li>Poskytujeme vy\u0161\u0161\u00ed zabezpe\u010den\u00ed osobn\u00edch dat a informac\u00ed nejen o v\u00e1s, ale i data va\u0161ich z\u00e1kazn\u00edk\u016f na na\u0161ich cloudov\u00fdch slu\u017eb\u00e1ch. Toto je potvrzeno nez\u00e1visl\u00fdm auditem, kter\u00fd se opakuje ka\u017ed\u00e9 3 roky.<\/li>\n<li>V\u011bt\u0161ina bezpe\u010dnostn\u00edch po\u017eadavk\u016f na SaaS slu\u017eby p\u0159\u00edmo vy\u017eaduje anebo vych\u00e1z\u00ed z mezin\u00e1rodn\u00edho standardu ISO 27018. Pokud s va\u0161imi z\u00e1kazn\u00edky budete \u0159e\u0161it bezpe\u010dnost dat, sta\u010d\u00ed \u0159\u00edct, \u017ee v\u00e1\u0161 poskytovatel spl\u0148uje ISO 27018 a GDRP.<\/li>\n<li>ISO 27018 tak\u00e9 znamen\u00e1, \u017ee poskytujeme maxim\u00e1ln\u00ed mo\u017enou pr\u00e1vn\u00ed ochranu u\u017eivatel\u016fm, kter\u00e1 je dostupn\u00e1.<\/li>\n<li>ISO 27018 prakticky zaru\u010duje, \u017ee va\u0161e osobn\u00ed data nevyu\u017eijeme pro reklamu a marketing, pokud k tomu ned\u00e1te v\u00fdslovn\u00fd souhlas. Z\u00e1rove\u0148 tato data nesm\u00edme sd\u00edlet s \u017e\u00e1dnou t\u0159et\u00ed stranou.<\/li>\n<li>Pokud by se objevil n\u011bjak\u00fd subdodavatel, kter\u00fd by mohl z\u00edskat by\u0165 jen potenci\u00e1ln\u00ed p\u0159\u00edstup k dat\u016fm, tak v\u00e1s o tom v\u017edy mus\u00edme informovat a vy m\u00e1te mo\u017enost vzn\u00e9st n\u00e1mitku, p\u0159\u00edpadn\u011b vypov\u011bd\u011bt smlouvu.<\/li>\n<\/ul>\n<h3>Z\u00e1v\u011br<\/h3>\n<p>Asi si dok\u00e1\u017eete ud\u011blat p\u0159edstavu, co vlastn\u011b ISO certifikace obn\u00e1\u0161\u00ed. Existuje soubor proces\u016f, kter\u00e9 mus\u00ed b\u00fdt zaji\u0161t\u011bny a z\u00e1rove\u0148 k nim mus\u00ed existovat odpov\u011bdn\u00e9 osoby. Nem\u016f\u017ee se st\u00e1t, \u017ee kdy\u017e n\u011bco nejde, tak za to nikdo nem\u016f\u017ee anebo nev\u00ed co s t\u00edm. To je naprosto nemysliteln\u00e9. V\u017edy existuj\u00ed konkr\u00e9tn\u00ed osoby, kter\u00e9 maj\u00ed za konkr\u00e9tn\u00ed proces odpov\u011bdnost a mus\u00ed dohl\u00e9dnout, aby v\u0161e fungovalo pomoc\u00ed opat\u0159en\u00ed, kter\u00e9 omez\u00ed riziko vzniku probl\u00e9mu (pravideln\u00e1 \u00fadr\u017eba, monitoring, kontrola log\u016f atd.) Tohle v\u0161e kontroluje velice d\u016fkladn\u011b nez\u00e1visl\u00fd auditor.<\/p>\n<p>A\u010dkoliv tvrd\u00edme, \u017ee certifikace d\u011bl\u00e1me hlavn\u011b pro na\u0161e z\u00e1kazn\u00edky a abychom mohli klidn\u011b sp\u00e1t, tak n\u00e1s tak\u00e9 udr\u017euj\u00ed ve st\u0159ehu. P\u0159ed ka\u017ed\u00fdm auditem c\u00edt\u00edte nervozitu a lad\u00edte v\u0161e k dokonalosti. V na\u0161em oboru je nejd\u016fle\u017eit\u011bj\u0161\u00ed neusnout a posouvat se neust\u00e1le kup\u0159edu a popravd\u011b ob\u010das p\u0159i revizi anebo vylep\u0161ov\u00e1n\u00ed firemn\u00edch proces\u016f p\u0159ijdeme na n\u00e1pady, kter\u00e9 n\u00e1s p\u011bkn\u011b nakopnou kup\u0159edu.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Na spu\u0161t\u011bn\u00ed slu\u017eby WEDOS Cloud jsme se dlouhou dobu p\u0159ipravovali. Prob\u00edhal nejen v\u00fdvoj software a rozs\u00e1hl\u00e9 testov\u00e1n\u00ed hardware, ale tak\u00e9 jsme se v\u011bnovali ot\u00e1zk\u00e1m pr\u00e1vn\u00edm, bezpe\u010dnostn\u00edm a jak to v\u0161e zakomponovat do sou\u010dasn\u00e9ho sv\u011bta. Kdy\u017e u\u017e jsme tomu v\u011bnovali tolik \u010dasu, tak n\u00e1s napadlo, \u017ee by st\u00e1lo za to m\u00edt i n\u011bjak\u00e9 nez\u00e1visl\u00e9 potvrzen\u00ed, a &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blog.wedos.com\/cs\/ziskali-jsme-dve-dulezite-cloudove-certifikace-iso-27017-a-iso-27018\" class=\"more-link\">Pokra\u010dovat ve \u010dten\u00ed<span class=\"screen-reader-text\"> &#8222;Z\u00edskali jsme dv\u011b d\u016fle\u017eit\u00e9 cloudov\u00e9 certifikace ISO 27017  a ISO 27018&#8220;<\/span><\/a><\/p>\n","protected":false},"author":9,"featured_media":63406,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[23,162,128,161,127,160],"class_list":["post-62441","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-spolecnost","tag-bezpecnost","tag-certifikace","tag-gdrp","tag-iso-27001","tag-iso-27017","tag-iso-27018"],"_links":{"self":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/62441","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/comments?post=62441"}],"version-history":[{"count":8,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/62441\/revisions"}],"predecessor-version":[{"id":63409,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/posts\/62441\/revisions\/63409"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media\/63406"}],"wp:attachment":[{"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/media?parent=62441"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/categories?post=62441"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.wedos.com\/cs\/wp-json\/wp\/v2\/tags?post=62441"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}