Routing rules

7-day intensive

Overall at least 75%, every domain at least 60%, and prerequisites met.

14-day balanced

Overall 60–74% or materially inconsistent domain results.

30-day foundation

Overall below 60%, a domain below 45%, or missing foundations.

These are Baitaphish recommendations, not provider rules or pass guarantees.

Choose your path

Experienced practitioners who meet prerequisites, score at least 75% overall, and have no domain below 60%.

  1. Day 18h

    Risk management and asset security

    Objectives
    1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11, 1.12, 2.1, 2.2, 2.3, 2.4, 2.5, 2.6
    Lesson
    Use management authority, obligations, ownership, risk, continuity, classification, handling, and lifecycle to frame decisions.
    Decision matrix
    Complete risk-response and control-classification matrices.
    Application
    Run CISSP-S01, S02, and S03.
    Recall
    Complete D1–D2 cards.
    Check
    Take D1–D2 checks and identify the accountable risk/data owner in every case.
    Remediation
    Below 70%: rewrite each technical answer as the first appropriate management action.
  2. Day 28h

    Security architecture and engineering

    Objectives
    3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10
    Lesson
    Apply design principles, models, platform risk, cryptography, facilities, physical controls, and lifecycle engineering.
    Decision matrix
    Complete cryptographic and control matrices.
    Application
    Run CISSP-S04.
    Recall
    Complete D3 cards.
    Check
    Take the D3 check and explain control purpose before product or mechanism.
    Remediation
    Below 70%: map each miss to security property, threat, control, and evidence.
  3. Day 38h

    Network security and IAM

    Objectives
    4.1, 4.2, 4.3, 5.1, 5.2, 5.3, 5.4, 5.5, 5.6
    Lesson
    Design trusted communication and identity lifecycle without confusing proofing, authentication, authorization, and access review.
    Decision matrix
    Complete network-protection and IAM matrices.
    Application
    Run CISSP-S05 and S06.
    Recall
    Complete D4–D5 cards.
    Check
    Take D4–D5 checks and trace two end-to-end access decisions.
    Remediation
    Below 70%: redraw trust boundaries and identity lifecycle before continuing.
  4. Day 48h

    Assessment and testing

    Objectives
    6.1, 6.2, 6.3, 6.4, 6.5
    Lesson
    Choose authorized, independent, safe, evidence-based assessment methods and communicate risk clearly.
    Decision matrix
    Complete the assessment-method matrix.
    Application
    Run CISSP-S07.
    Recall
    Complete D6 cards.
    Check
    Take the D6 check and defend method, scope, evidence, and limitations.
    Remediation
    Any test without authorization, safety boundary, or follow-up fails remediation.
  5. Day 59h

    Operations and software security

    Objectives
    7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 7.8, 7.9, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15, 8.1, 8.2, 8.3, 8.4, 8.5
    Lesson
    Coordinate investigations, monitoring, change, incidents, recovery, continuity, safety, SDLC, suppliers, and secure coding.
    Decision matrix
    Complete incident/recovery and software/supplier matrices.
    Application
    Run CISSP-S08, S09, and S10.
    Recall
    Complete D7–D8 and mixed cards.
    Check
    Take D7–D8 plus cumulative checks.
    Remediation
    Any domain below 70% becomes the first Day 6 repair block.
  6. Day 69h

    Fixed-length Practice A

    Objectives
    1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11, 1.12, 2.1, 2.2, 2.3, 2.4, 2.5, 2.6, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 4.1, 4.2, 4.3, 5.1, 5.2, 5.3, 5.4, 5.5, 5.6, 6.1, 6.2, 6.3, 6.4, 6.5, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 7.8, 7.9, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15, 8.1, 8.2, 8.3, 8.4, 8.5
    Lesson
    Review only missed objectives after the closed-book assessment.
    Decision matrix
    Rebuild the two weakest matrices.
    Application
    Repeat the scoring step from one missed scenario.
    Recall
    Use error-log cards only.
    Check
    Complete fresh timed 125-item Practice A; it is not adaptive and does not reproduce ISC2 CAT.
    Remediation
    Below 80% or any domain below 70%: enter the 14-day extension before Practice B.
  7. Day 79h

    Fixed-length Practice B and final review

    Objectives
    1.1, 1.2, 1.3, 1.4, 1.5, 1.6, 1.7, 1.8, 1.9, 1.10, 1.11, 1.12, 2.1, 2.2, 2.3, 2.4, 2.5, 2.6, 3.1, 3.2, 3.3, 3.4, 3.5, 3.6, 3.7, 3.8, 3.9, 3.10, 4.1, 4.2, 4.3, 5.1, 5.2, 5.3, 5.4, 5.5, 5.6, 6.1, 6.2, 6.3, 6.4, 6.5, 7.1, 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 7.8, 7.9, 7.10, 7.11, 7.12, 7.13, 7.14, 7.15, 8.1, 8.2, 8.3, 8.4, 8.5
    Lesson
    Close repeated misses and rehearse ethics, authority, business priority, risk, and evidence-first reasoning.
    Decision matrix
    Complete all matrices from a blank copy.
    Application
    Explain three scenario decisions and rejected alternatives without notes.
    Recall
    Final mixed recall.
    Check
    Complete fresh timed 125-item Practice B and every readiness hard gate.
    Remediation
    If any hard gate fails, continue focused remediation; do not label exam-ready.