course · api securitycurso · seguridad de apis
APIs run the internet. Learn to secure them properly.Las APIs hacen funcionar internet. Aprende a protegerlas como se debe.
36 hours · nine modules · task-based exam36 horas · nueve módulos · examen basado en tareas
A practical approach to agile and automation techniques in API security: hands-on, DevSecOps-first, and built for the way APIs are actually attacked.Un enfoque práctico de técnicas ágiles y de automatización en la seguridad de APIs: práctico, con DevSecOps primero y pensado para la forma en que realmente se atacan las APIs.
sec. 01 · who it's forsec. 01 · para quién es
APIs are most of the traffic, and most of the risk.Las APIs son la mayor parte del tráfico, y la mayor parte del riesgo.
APIs now account for around 80% of total internet traffic, and that makes them one of the largest attack surfaces you own. CASP is for security professionals, offensive-security and red-team engineers, application-security engineers, developers and DevOps engineers. You'll want basic Linux and familiarity with the OWASP Top 10. Over 36 hours, 8 hours of video plus 28 hours of hands-on work across 40+ exercises, you learn to attack and defend APIs and bake that security into your pipeline. Comes with 60 days of lab access and 3 years of on-demand access.Las APIs representan hoy alrededor del 80% del tráfico total de internet, y eso las convierte en una de las superficies de ataque más grandes que tienes. CASP es para profesionales de seguridad, ingenieros de seguridad ofensiva y de red team, ingenieros de seguridad de aplicaciones, desarrolladores e ingenieros de DevOps. Conviene tener conocimientos básicos de Linux y familiaridad con el OWASP Top 10. A lo largo de 36 horas, 8 horas de video más 28 horas de trabajo práctico en más de 40 ejercicios, aprendes a atacar y defender APIs e integrar esa seguridad en tu pipeline. Incluye 60 días de acceso al laboratorio y 3 años de acceso bajo demanda.
sec. 02 · syllabussec. 02 · temario
DevSecOps runs through every module.DevSecOps recorre cada módulo.
Introduction to API SecurityIntroducción a la seguridad de APIs
How APIs are exposed, why they fail, and the shape of the modern API attack surface.Cómo quedan expuestas las APIs, por qué fallan y cómo es la superficie de ataque de APIs actual.
API Security Tools of the TradeHerramientas clave de seguridad de APIs
The tooling you'll use to test, intercept and harden APIs in practice.Las herramientas que usarás para probar, interceptar y endurecer APIs en la práctica.
Authentication Attacks & DefensesAtaques y defensas de autenticación
OAuth 2.0 and 2.1, JWT handling, and the authentication flaws attackers rely on.OAuth 2.0 y 2.1, manejo de JWT y las fallas de autenticación en las que se apoyan los atacantes.
Authorization Attacks & DefensesAtaques y defensas de autorización
Broken object-level and function-level authorization, and RBAC/ABAC/ReBAC done right.Autorización rota a nivel de objeto y de función, y RBAC/ABAC/ReBAC bien hechos.
Input-Validation Threats & DefensesAmenazas y defensas de validación de entradas
Injection, mass assignment and the validation patterns that stop them.Inyección, asignación masiva y los patrones de validación que las frenan.
OWASP API Top 10OWASP API Top 10
Every entry worked through hands-on, with exploitation and mitigation.Cada entrada trabajada de forma práctica, con explotación y mitigación.
API Security DefensesDefensas de seguridad de APIs
Rate limiting, gateways, secrets and the controls that hold under load.Rate limiting, gateways, secretos y los controles que aguantan bajo carga.
Implementing API Security MechanismsImplementar mecanismos de seguridad de APIs
Put the controls in place across REST, GraphQL and SOAP.Pon en marcha los controles en REST, GraphQL y SOAP.
API Security the DevSecOps WaySeguridad de APIs al estilo DevSecOps
SCA, SAST and DAST in CI/CD, HashiCorp Vault, and continuous API assurance.SCA, SAST y DAST en CI/CD, HashiCorp Vault y aseguramiento continuo de APIs.
Technologies covered: OAuth 2.0 / 2.1 · JWT · RBAC / ABAC / ReBAC · REST / GraphQL / SOAP · SCA / SAST / DAST in CI/CD · HashiCorp Vault · OWASP ASVS.Tecnologías que se cubren: OAuth 2.0 / 2.1 · JWT · RBAC / ABAC / ReBAC · REST / GraphQL / SOAP · SCA / SAST / DAST en CI/CD · HashiCorp Vault · OWASP ASVS.
sec. 03 · certification & examsec. 03 · certificación y examen
Proven by solving real challenges.Se demuestra resolviendo retos reales.
The exam is task-oriented: five real challenges, six hours. Pass, and you hold the Certified API Security Professional (CASP) credential.El examen está orientado a tareas: cinco retos reales, seis horas. Apruébalo y obtienes la credencial Certified API Security Professional (CASP).
sec. 04 · delivered withsec. 04 · impartido con
Authored by Practical DevSecOps.Creado por Practical DevSecOps.
CASP is a certification by Practical DevSecOps (Hysn Technologies Inc). Arxia offers and facilitates it, so the credential comes from a recognized security-training specialist and the training ties directly into how your team builds and ships.CASP es una certificación de Practical DevSecOps (Hysn Technologies Inc). Arxia la ofrece y la facilita, de modo que la credencial viene de un especialista reconocido en formación en seguridad y la formación se conecta directamente con la forma en que tu equipo construye y despliega.
sec. 05 · questionssec. 05 · preguntas
Frequently askedPreguntas frecuentes
Authentication and authorization attacks and defenses, input-validation threats, the OWASP API Top 10, and how to build API security into a DevSecOps pipeline, all hands-on across nine modules.Ataques y defensas de autenticación y autorización, amenazas de validación de entradas, el OWASP API Top 10 y cómo integrar la seguridad de APIs en un pipeline de DevSecOps, todo de forma práctica a lo largo de nueve módulos.
36 hours total: about 8 hours of video plus 28 hours of hands-on work across 40+ exercises. It runs online, with 60 days of lab access and 3 years of on-demand access to the material.36 horas en total: unas 8 horas de video más 28 horas de trabajo práctico en más de 40 ejercicios. Se imparte en línea, con 60 días de acceso al laboratorio y 3 años de acceso al material bajo demanda.
It's task-oriented. You get five real challenges to solve in six hours, need at least 80% to pass, and have 24 hours to submit your report. Pass, and you hold the CASP credential.Está orientado a tareas. Tienes cinco retos reales que resolver en seis horas, necesitas al menos 80% para aprobar y cuentas con 24 horas para entregar tu informe. Apruébalo y obtienes la credencial CASP.
Security professionals, offensive-security and red-team engineers, application-security engineers, developers and DevOps engineers. You'll want basic Linux and familiarity with the OWASP Top 10.Profesionales de seguridad, ingenieros de seguridad ofensiva y de red team, ingenieros de seguridad de aplicaciones, desarrolladores e ingenieros de DevOps. Conviene tener conocimientos básicos de Linux y familiaridad con el OWASP Top 10.
OAuth 2.0 and 2.1, JWT, RBAC/ABAC/ReBAC, REST, GraphQL and SOAP, SCA/SAST/DAST in CI/CD, HashiCorp Vault, and the OWASP ASVS.OAuth 2.0 y 2.1, JWT, RBAC/ABAC/ReBAC, REST, GraphQL y SOAP, SCA/SAST/DAST en CI/CD, HashiCorp Vault y el OWASP ASVS.
Pricing depends on cohort size and delivery format. Ask us for current CASP pricing and the next available cohort, we'll get back to you within two business days.El precio depende del tamaño de la cohorte y del formato de entrega. Pídenos el precio actual de CASP y la próxima cohorte disponible, te responderemos en un máximo de dos días hábiles.
next stepsiguiente paso
Let's find your first win.Encontremos tu primera victoria.
Tell us how your team works today and what's slowing it down. We'll point you to the right starting line. For most teams, that's a one-day AI Ignite workshop.Cuéntanos cómo trabaja tu equipo hoy y qué lo frena. Te indicaremos el mejor punto de partida. Para la mayoría de los equipos, es un taller AI Ignite de un día.
enrollinscríbete
Enroll, or ask about the next cohort.Inscríbete o pregunta por la próxima cohorte.
Tell us who's taking CASP and when you'd like to start. We'll confirm the next cohort, pricing and lab access.Cuéntanos quién va a tomar CASP y cuándo te gustaría empezar. Te confirmamos la próxima cohorte, el precio y el acceso al laboratorio.