{"id":5995,"date":"2025-03-06T14:59:56","date_gmt":"2025-03-06T13:59:56","guid":{"rendered":"https:\/\/pcihispano.com\/?p=5995"},"modified":"2026-05-06T19:14:41","modified_gmt":"2026-05-06T17:14:41","slug":"las-dos-caras-de-los-escaneos-autenticados-pci-dss-req-11-3-1-2","status":"publish","type":"post","link":"https:\/\/www.pcihispano.com\/en\/las-dos-caras-de-los-escaneos-autenticados-pci-dss-req-11-3-1-2\/","title":{"rendered":"The two sides of the authenticated scans (PCI DSS req. 11.3.1.2)"},"content":{"rendered":"<p><span class=\"intro-text\">Another relevant change in PCI DSS version 4.0 was the evolution of internal vulnerability scans from a network-based approach (PCI DSS v3.2.1) to an authenticated approach, which allows full visibility into the internal configuration of the analyzed host. This new approach can be seen as a substantive improvement from a security point of view, but it opens the door to another problem: the management of the administrative credentials and permissions used by this type of scans. In this article we explain how to avoid surprises and implement this control in a safe way.<\/span><\/p>\n<p>As explained in the article <a href=\"https:\/\/www.pcihispano.com\/en\/analisis-de-pci-dss-v4-0-parte-vi-requerimientos-10-y-11\/\" target=\"_blank\" rel=\"noopener\">Analysis of PCI DSS v4.0 Part VI: Requirements 10 and 11<\/a>, probably one of the most relevant changes in PCI DSS is the inclusion of the concept of \u201cauthenticated scans\u201d (<em>authenticated scanning<\/em>). This approach allows internal scans to go beyond the detection of vulnerabilities from the network point of view and evolve towards the identification of vulnerabilities from the point of view of the asset (host), giving greater visibility to the results and incorporating not only the vulnerabilities of the services published in data networks but also of the local software and its configuration.<\/p>\n<div id=\"attachment_400\" style=\"width: 852px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-400\" class=\"wp-image-400\" src=\"https:\/\/i0.wp.com\/pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?resize=842%2C505&#038;ssl=1\" alt=\"\" width=\"842\" height=\"505\" srcset=\"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?w=2314&amp;ssl=1 2314w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?resize=300%2C180&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?resize=1024%2C614&amp;ssl=1 1024w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?resize=768%2C460&amp;ssl=1 768w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?resize=1536%2C921&amp;ssl=1 1536w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?resize=2048%2C1228&amp;ssl=1 2048w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?resize=500%2C300&amp;ssl=1 500w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?resize=1000%2C600&amp;ssl=1 1000w, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/net_scan_vs_auth_scan.png?w=1800&amp;ssl=1 1800w\" sizes=\"auto, (max-width: 842px) 100vw, 842px\" \/><p id=\"caption-attachment-400\" class=\"wp-caption-text\">Differences between traditional vulnerability scanning and authenticated scanning<\/p><\/div>\n<p>The requirement in question is 11.3.1.2, which reads:<\/p>\n<div class=\"su-note\"  style=\"border-color:#dbdbdb;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;\"><div class=\"su-note-inner su-u-clearfix su-u-trim\" style=\"background-color:#f5f5f5;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;\"><em>11.3.1.2 Internal vulnerability scans must be executed via authenticated scans as follows:<\/em><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li><em>Systems that cannot accept credentials for authenticated scanning must be documented.<\/em><\/li>\n<li><em>Sufficient privileges should be used for those systems that accept credentials for scanning.<\/em><\/li>\n<li><em>If the accounts used for authenticated scanning can be used for interactive session initiation, then these accounts must be managed in accordance with requirement 8.2.2.<\/em><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/div><\/div><\/li>\n<\/ul>\n<h4>The good side of authenticated scans<\/h4>\n<p>As I said <a href=\"https:\/\/en.wikiquote.org\/wiki\/Benjamin_Disraeli\" target=\"_blank\" rel=\"noopener\">Benjamin Disraeli<\/a>, As a rule, the man who is most successful in life is the one who has the best information. From a security point of view, the more information you have about an asset, the definition of its controls can be refined in a more adjusted way. And this is the case with authenticated scans: provide more information to the entity about the status of a particular asset, including exposed ports and protocols, running services, users and groups, permissions, connected peripherals, updates, etc. allowing to know its security level at a particular time.<\/p>\n<h4>The Bad Face of Authenticated Scans<\/h4>\n<p>However, to achieve that level of visibility in an asset, generic permissions are not enough: <span class=\"highlight\">administration privileges are required <\/span>.<\/p>\n<p>From a technical point of view, this can be achieved through two approaches:<\/p>\n<ul>\n<li><strong>Through agents<\/strong>: The installation of an agent in the <em>host<\/em> to be analysed (local agent). This agent must be executed with administrative privileges so that it can properly evaluate the system without restrictions.<\/li>\n<li><strong>No agents (<em>agentless<\/em>)<\/strong>: In systems where you do not want or cannot install agents (either for incompatibility with supported operating systems, for the use of <em>appliances<\/em>, etc.), scans can be performed remotely without local agents installed. To do this, the scanner must have a remote method and connection (SSH, SNMP, WMI, API, shared resources, etc.) and have valid administration credentials (usernames and passwords or digital certificates) that must be provided to the scanner to be able to remotely authenticate and execute the necessary tests.<\/li>\n<\/ul>\n<p>And this is precisely where the irony comes from, since <span class=\"highlight\">the vulnerability scanning tool automatically becomes an attack vector:<\/span><\/p>\n<ul>\n<li>If the scanning tool console is compromised, the attacker will be able to control the agents and\/or access the stored credentials.<\/li>\n<li>If installed local agents are compromised, the systems that have those agents will also be compromised (as they run with administration privileges).<\/li>\n<li>If the credentials used for agentless scans (which are supposed to have administrative privileges) are compromised, all systems where authentication can be done will be compromised.<\/li>\n<li>Because the scanner must have unrestricted access at the network level in order to analyze the target host, an attacker can use those privileges to access the networks of the systems to be scanned.<\/li>\n<\/ul>\n<h4>Recommendations<\/h4>\n<p>As indicated in the same requirement, these accounts must be managed through requirement 8.2.2:<\/p>\n<div class=\"su-note\"  style=\"border-color:#dbdbdb;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;\"><div class=\"su-note-inner su-u-clearfix su-u-trim\" style=\"background-color:#f5f5f5;border-color:#ffffff;color:#333333;border-radius:3px;-moz-border-radius:3px;-webkit-border-radius:3px;\"><em>8.2.2 Shared or generic group identifiers (IDs) or other shared authentication credentials should only be used when exceptionally necessary, and should be managed as follows:<\/em><\/p>\n<ul>\n<li><em>The use of ID is prevented unless it is necessary for an exceptional circumstance.<\/em><\/li>\n<li><em>Use is limited to the time necessary for the exceptional circumstance.<\/em><\/li>\n<li><em>The business justification for the use is documented.<\/em><\/li>\n<li><em>The address explicitly approves its use.<\/em><\/li>\n<li><em>The identity of the individual user is confirmed before granting access to an account.<\/em><\/li>\n<li><em>Each action performed is attributable to an individual user.<br \/>\n<\/em><\/li>\n<\/ul>\n<\/div><\/div>\n<p>These controls may be fine in certain circumstances, but depending on the scanning tool and the infrastructure to be analyzed, they may fall short, exposing the institution to potential risks.<\/p>\n<p>Therefore, from PCI Hispano we recommend the implementation of the following additional controls:<\/p>\n<ul>\n<li>Stipulate specific time periods for the scans and monitor any actions performed with the accounts used in the authenticated scans outside those periods.<\/li>\n<li>For centralized accounts (e.g. active directory accounts or LDAPs):\n<ul>\n<li>Rotate frequently the passwords used.<\/li>\n<li>Enable these accounts only when scan periods are active.<\/li>\n<li>If possible, remove administrative privileges to the account when not in use.<\/li>\n<\/ul>\n<\/li>\n<li>Depending on the operating system restrictions to be analyzed, employ privilege escalation controls (su, sudo, etc.)<\/li>\n<li>Restrict the interactive use of the account used for authenticated scans. For example, in Unix systems you can be assigned a <em>shell<\/em> non-interactive as <em>\/bin\/nologin, \/bin\/false<\/em> o <em>\/bin\/true<\/em>.<\/li>\n<li>Enable firewall rules at the perimeter or local level on the systems that support it to allow remote access from the scanner only during the time periods in which the scan is being done. Once finished, the rules must be disabled.<\/li>\n<li>Preferably use certificate-based authentication instead of passwords.<\/li>\n<li>If the organization has a privileged access management system (<em>Privileged Access Management<\/em> \u2013 PAM), then link the accounts used in the authenticated scans with that tool.<\/li>\n<\/ul>\n<p>Finally, <span class=\"highlight\">it is not recommended to run authenticated scans with accounts without administrative privileges or manually profiled privileges, as scan results may be erroneous, partial or have false positives<\/span>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Another relevant change in PCI DSS version 4.0 was the evolution of internal vulnerability scans from a network-based approach (PCI DSS v3.2.1) to an authenticated approach, allowing full visibility of the [\u2026]<\/p>","protected":false},"author":2,"featured_media":6050,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1,354],"tags":[294,72,295,296,71],"class_list":["post-5995","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-contenido","category-pcidss","tag-autenticado","tag-escaneo","tag-permisos","tag-privilegios","tag-scan"],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/02\/a7bdc589-257b-4cab-a72f-7c87a8af256d.jpg?fit=1024%2C1024&ssl=1","jetpack-related-posts":[{"id":391,"url":"https:\/\/www.pcihispano.com\/en\/analisis-de-pci-dss-v4-0-parte-vi-requerimientos-10-y-11\/","url_meta":{"origin":5995,"position":0},"title":"An\u00e1lisis de PCI DSS v4.0 Parte VI: Requerimientos 10 y 11","author":"David Acosta","date":"septiembre 15, 2022","format":false,"excerpt":"En esta sexta entrega de la serie \u201cAn\u00e1lisis de PCI DSS v4.0\u201d se analizar\u00e1n los requerimientos 10 y 11 del est\u00e1ndar PCI DSS v4.0. Estos requerimientos hacen parte del grupo 5. Regularly Monitor and Test Networks, que continua con el mismo nombre de la versi\u00f3n 3.2.1 del est\u00e1ndar. El objetivo\u2026","rel":"","context":"In &quot;An\u00e1lisis de PCI DSS v4.0&quot;","block_context":{"text":"An\u00e1lisis de PCI DSS v4.0","link":"https:\/\/www.pcihispano.com\/en\/category\/pci-dss-4-0\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/Parte6.png?fit=1200%2C672&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/Parte6.png?fit=1200%2C672&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/Parte6.png?fit=1200%2C672&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/Parte6.png?fit=1200%2C672&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/09\/Parte6.png?fit=1200%2C672&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":176,"url":"https:\/\/www.pcihispano.com\/en\/analisis-de-pci-dss-v4-0-parte-iv-requerimientos-5-y-6\/","url_meta":{"origin":5995,"position":1},"title":"An\u00e1lisis de PCI DSS v4.0 \u2013 Parte IV: Requerimientos 5 y 6","author":"David Acosta","date":"agosto 18, 2022","format":false,"excerpt":"En esta cuarta entrega de la serie \u201cAn\u00e1lisis de PCI DSS 4.0\u201d se presenta una revisi\u00f3n a los cambios en los requerimientos 5 y 6 del est\u00e1ndar PCI DSS ocurridos entre las versiones 3.2.1 y 4.0. Estos dos requerimientos est\u00e1n enfocados a la protecci\u00f3n a nivel de software para prevenir,\u2026","rel":"","context":"In &quot;An\u00e1lisis de PCI DSS v4.0&quot;","block_context":{"text":"An\u00e1lisis de PCI DSS v4.0","link":"https:\/\/www.pcihispano.com\/en\/category\/pci-dss-4-0\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte4b.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte4b.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte4b.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte4b.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte4b.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":9583,"url":"https:\/\/www.pcihispano.com\/en\/diferencias-entre-escaneos-de-vulnerabilidades-y-pruebas-de-penetracion-en-pci-dss\/","url_meta":{"origin":5995,"position":2},"title":"Diferencias entre escaneos de vulnerabilidades y pruebas de penetraci\u00f3n en PCI DSS","author":"David Acosta","date":"diciembre 4, 2025","format":false,"excerpt":"Como parte de las actividades peri\u00f3dicas de monitorizaci\u00f3n del estado de seguridad, el est\u00e1ndar PCI DSS exige realizar una serie de evaluaciones t\u00e9cnicas para identificar de forma temprana posibles problemas de seguridad en los activos del \u00e1mbito de cumplimiento y en los controles de seguridad desplegados. Entre estas actividades se\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/nmap.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/nmap.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/nmap.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/nmap.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/12\/nmap.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":98,"url":"https:\/\/www.pcihispano.com\/en\/analisis-de-pci-dss-v4-0-parte-1-introduccion\/","url_meta":{"origin":5995,"position":3},"title":"An\u00e1lisis de PCI DSS v4.0 &#8211; Parte I: Introducci\u00f3n","author":"David Acosta","date":"agosto 17, 2022","format":false,"excerpt":"En esta primera parte de esta serie \"An\u00e1lisis de PCI DSS v4.0\" se analizar\u00e1 la historia detr\u00e1s de la versi\u00f3n 4.0 del est\u00e1ndar, las variables que influyeron en su cambio y el proceso de revisi\u00f3n y publicaci\u00f3n asociado. A continuaci\u00f3n, en entregas subsiguientes, se realizar\u00e1 una revisi\u00f3n a los cambios\u2026","rel":"","context":"In &quot;An\u00e1lisis de PCI DSS v4.0&quot;","block_context":{"text":"An\u00e1lisis de PCI DSS v4.0","link":"https:\/\/www.pcihispano.com\/en\/category\/pci-dss-4-0\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte1.png?fit=1200%2C675&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte1.png?fit=1200%2C675&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte1.png?fit=1200%2C675&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte1.png?fit=1200%2C675&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2022\/08\/parte1.png?fit=1200%2C675&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":3501,"url":"https:\/\/www.pcihispano.com\/en\/nueva-version-de-pci-dss-4-0-1\/","url_meta":{"origin":5995,"position":4},"title":"Nueva versi\u00f3n de PCI DSS: 4.0.1","author":"David Acosta","date":"junio 12, 2024","format":false,"excerpt":"El 11 de junio de 2024 el PCI SSC public\u00f3 la versi\u00f3n 4.0.1 del est\u00e1ndar PCI DSS, que remplaza a la versi\u00f3n 4.0 publicada en marzo de 2022 Esta nueva versi\u00f3n contiene revisiones menores, correcciones tipogr\u00e1ficas y de formato y aclaraciones sin a\u00f1adir o remover requerimientos de la versi\u00f3n 4.0.\u2026","rel":"","context":"In &quot;Noticias&quot;","block_context":{"text":"Noticias","link":"https:\/\/www.pcihispano.com\/en\/category\/noticias\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/06\/PCI_DSS_v4.0.1.png?fit=1200%2C762&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/06\/PCI_DSS_v4.0.1.png?fit=1200%2C762&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/06\/PCI_DSS_v4.0.1.png?fit=1200%2C762&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/06\/PCI_DSS_v4.0.1.png?fit=1200%2C762&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2024\/06\/PCI_DSS_v4.0.1.png?fit=1200%2C762&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":6697,"url":"https:\/\/www.pcihispano.com\/en\/gestion-de-vulnerabilidades-en-pci-dss-conectando-todos-los-controles-relacionados\/","url_meta":{"origin":5995,"position":5},"title":"Gesti\u00f3n de vulnerabilidades en PCI DSS: Conectando todos los controles relacionados","author":"David Acosta","date":"junio 5, 2025","format":false,"excerpt":"La gesti\u00f3n de vulnerabilidades es una de las tareas m\u00e1s desgastantes en un entorno PCI DSS, ya que se requiere monitorizar peri\u00f3dicamente la publicaci\u00f3n de notificaciones por parte de los fabricantes, revisar los reportes de los escaneos y pruebas de penetraci\u00f3n, asignar una prioridad a cada vulnerabilidad identificada y -\u00a0\u2026","rel":"","context":"In &quot;Contenido general&quot;","block_context":{"text":"Contenido general","link":"https:\/\/www.pcihispano.com\/en\/category\/contenido\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/06\/bg.png?fit=1200%2C674&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/06\/bg.png?fit=1200%2C674&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/06\/bg.png?fit=1200%2C674&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/06\/bg.png?fit=1200%2C674&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/www.pcihispano.com\/wp-content\/uploads\/2025\/06\/bg.png?fit=1200%2C674&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/5995","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/comments?post=5995"}],"version-history":[{"count":1,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/5995\/revisions"}],"predecessor-version":[{"id":11720,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/posts\/5995\/revisions\/11720"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media\/6050"}],"wp:attachment":[{"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/media?parent=5995"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/categories?post=5995"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pcihispano.com\/en\/wp-json\/wp\/v2\/tags?post=5995"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}