# Learning Guide: CISSP in Twelve Weeks

How to run the twelve weeks at about ten hours a week. The course map in `course.md` lists the
modules; this guide is the weekly protocol.

## The week, every week

| Block | Hours | What you do |
|---|---|---|
| Modules | 5 to 6 | Three modules in Tracks 1 and 2 (two in Track 3). For each: read the module (45 min), read the book chapter named in its Sources (60 min), do the Module check and the Build it yourself artifact (45 min). |
| Problems | 2 | Two problem lessons from the ladder. Write your first pass before reading on. The artifact is the point; the vocabulary section is the reward. |
| Review | 1 | Reopen last week's Common trap sections. Redo one faded practice item per module with the solution closed. Update the error log. |
| Tutor session | 1 | Open this folder in Claude Code and ask to be quizzed on a module or a concept. The tutor poses first, you attempt, it repairs one thing, you try again. It records what you showed in `learner/state.md`. |

Do the modules in order. Each one's Figure it out from scratch cards and Common trap assume the
earlier ones. Problems can be taken in order or by interest; each names what it extends.

## The twelve weeks

| Week | Modules | Problems | Milestone |
|---|---|---|---|
| 1 | 01 Think Like the Risk Owner, 02 Governance, 03 Risk and ALE | P01, P02 | Take the LearnZapp diagnostic. Record the domain scores as the week-1 baseline in the error log. |
| 2 | 04 Law and Privacy, 05 Business Continuity, 06 People | P03, P04 | |
| 3 | 07 Threat Modeling and Supply Chain, 08 Classification, 09 Data States | P05, P06, P07 | Track 1 gate: the one-page client risk memo from P07. Watch the Domain 1 MindMap. |
| 4 | 10 Design and Models, 11 System Vulnerabilities, 12 Cryptography I | P08, P09 | |
| 5 | 13 Cryptography II, 14 Physical Security, 15 Network Architecture | P10, P11 | |
| 6 | 16 Secure Communications, 17 Identity, 18 Access Control | P12, P13, P14 | Track 2 gate: the access and network design from P14. Book the exam for the end of week 12. |
| 7 | 19 Assessment and Testing, 20 Operations | P15, P16 | Start daily practice questions (20 a day, by domain, logged). |
| 8 | 21 Incident Response, 22 Resilience and DR | P17, P18 | |
| 9 | 23 Software Development, 24 Application Attacks | P19 | |
| 10 | 25 The Exam | P20 capstone | First full-length practice set. Error log by domain and by reason. Start the Patterns drills. |
| 11 | Review by weakest domain | | Second full-length set. Reread the Common trap of every module you missed. |
| 12 | Light review, rest, exam | | Third set early in the week. Stop studying two days before. Sleep. |

## The error log

One row per missed practice question: date, domain, module, the reason (did not know the fact;
knew the fact and picked the technician's answer; misread the superlative; ran out of time). By
week 10 the reason column, not the domain column, tells you what to fix. Module 25 ships the
template.

## What done looks like

- Every module marked complete, with its Build it yourself artifact written and self-scored
  against the rubric.
- The three gate artifacts (P07 memo, P14 design, P20 program) exist and would survive a
  reading by a client.
- Two full-length practice sets at or above the passing line by the book's scoring, with the
  error log showing most misses as reasoning errors you can name, not unknown facts.
- The playbook's six drills answered correctly without looking at the cards.

## Studying with the tutor

Say "quiz me on module 03" or "study the ALE concept with me". The tutor reads
`learner/state.md`, proposes where to start, poses a problem from the module, and waits for your
attempt. It will not explain first. It corrects one thing per turn, up a ladder of hints, and
reveals the answer only after about three real attempts. Turn off reply auto-suggestions for the
session so the attempt is yours. Each session ends with a record in `learner/records/` and an
updated `state.md`, so the next session starts where this one stopped.
