Skip to main content
Image coming soon

SEC5173 Mastering CIS Controls for Institutional Advancement Leaders

$199.00
Adding to cart… The item has been added

What is the CIS Controls for Institutional Advancement course about?

As schools adopt more SaaS tools for fundraising, communications, and student data, advancement teams are increasingly involved in vendor assessments and compliance discussions. Yet without a structured framework, their input can be overlooked or seen as non-technical.

What situation is the CIS Controls for Institutional Advancement for?

As schools adopt more SaaS tools for fundraising, communications, and student data, advancement teams are increasingly involved in vendor assessments and compliance discussions. Yet without a structured framework, their input can be overlooked or seen as non-technical.

What do you take away from the CIS Controls for Institutional Advancement course?

Lead vendor selection discussions with a recognized security framework in hand Map advancement tools to CIS Controls for internal risk alignment Speak confidently about control maturity in cross-departmental meetings Anticipate audit triggers related to donor and student data handling Document due diligence in a way that satisfies compliance and leadership.

What's included with your purchase?

12 modules with 12 chapters each (144 chapters) Downloadable templates and worked examples for every module Hand-built implementation playbook delivered alongside course access 30-day money-back guarantee.

What does the CIS Controls for Institutional Advancement cover on delivery and format?

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access. Time investment: Approximately 3-4 hours per module, designed for busy practitioners to complete in short sessions.

How does this compare to the alternatives?

Unlike generic compliance courses, this program is tailored to advancement leaders in mission-driven institutions and grounded in the CIS Controls framework adopted by peer organizations.

What does the CIS Controls for Institutional Advancement cover on frequently asked?

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

How is the CIS Controls for Institutional Advancement delivered?

The CIS Controls for Institutional Advancement is fully self-paced with immediate online access after enrolment. Access does not expire and future updates are included at no cost. A certificate of completion is issued by The Art of Service when you finish.

Closely related courses: CIS Controls for Senior Finance Leaders in Regulated, More accurate control implementation with CIS Controls, Broader Security Control Scope with CIS Controls, Premium Engagement Picks with CIS Controls.

More answers: what you get with every course, refund policy, all help answers.

A tailored course, built for your situation

Mastering CIS Controls for Institutional Advancement Leaders

Build authority in technical oversight and decision influence within mission-driven institutions.

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.
Advancement leaders often sit outside core IT governance, but their voice matters in vendor trust and data integrity decisions.

The situation this course is for

As schools adopt more SaaS tools for fundraising, communications, and student data, advancement teams are increasingly involved in vendor assessments and compliance discussions. Yet without a structured framework, their input can be overlooked or seen as non-technical.

Who this is for

Senior advancement leaders at private schools and nonprofits who influence vendor selection, data governance, and institutional trust.

Who this is not for

Entry-level fundraisers, individual contributors without cross-functional influence, or IT staff focused solely on technical implementation.

What you walk away with

  • Lead vendor selection discussions with a recognized security framework in hand
  • Map advancement tools to CIS Controls for internal risk alignment
  • Speak confidently about control maturity in cross-departmental meetings
  • Anticipate audit triggers related to donor and student data handling
  • Document due diligence in a way that satisfies compliance and leadership

The 12 modules (with all 144 chapters)

Module 1. CIS Controls and the Advancement Function
Introduces the relevance of CIS Controls to advancement operations, focusing on where donor systems intersect with institutional cybersecurity.
12 chapters in this module
  1. Why CIS Controls matter beyond IT
  2. Mapping advancement tools to control domains
  3. The role of non-technical leaders in control adoption
  4. Data stewardship in fundraising platforms
  5. Compliance expectations in private education
  6. How advancement decisions impact audit outcomes
  7. Integrating security into donor engagement
  8. Understanding vendor risk from a leadership view
  9. The evolution of trust frameworks in schools
  10. Connecting mission to control maturity
  11. Assessing third-party platforms
  12. Building a baseline for cross-department alignment
Module 2. Understanding the CIS Top 20
Breaks down each of the 20 CIS Critical Security Controls with examples drawn from school and nonprofit environments.
12 chapters in this module
  1. Control 1: Inventory of authorized devices
  2. Control 2: Inventory of unauthorized devices
  3. Control 3: Secure configurations for hardware
  4. Control 4: Continuous vulnerability assessment
  5. Control 5: Controlled use of administrative privileges
  6. Control 6: Maintenance of secure configurations
  7. Control 7: Email and web browser protections
  8. Control 8: Malware defenses
  9. Control 9: Limitation of network ports
  10. Control 10: Data recovery capabilities
  11. Control 11: Secure configurations for network devices
  12. Control 12: Boundary defense
Module 3. Advancement Systems and Control Alignment
Applies CIS Controls to common platforms like Salesforce, donor databases, and communication tools.
12 chapters in this module
  1. Mapping CRM platforms to control domains
  2. Donor data encryption standards
  3. Third-party integration risks
  4. User access reviews for fundraising teams
  5. Audit logging in advancement tools
  6. Single sign-on and identity management
  7. Data retention policies
  8. Breach detection in communication systems
  9. Cloud provider security posture
  10. Phishing risk in alumni outreach
  11. Secure file sharing practices
  12. Mobile device management
Module 4. Influencing Vendor Selection
Equips leaders to shape vendor due diligence with structured questions based on CIS Controls.
12 chapters in this module
  1. Building a vendor scorecard
  2. Security questionnaire design
  3. Evaluating SOC 2 reports
  4. Assessing data ownership terms
  5. Incident response commitments
  6. Subprocesser risk review
  7. Penetration testing disclosures
  8. Patch management timelines
  9. Data portability and exit rights
  10. Insurance and liability coverage
  11. GDPR and student data alignment
  12. Oversight handoff to IT teams
Module 5. Building Internal Influence
Develops strategies for non-technical leaders to be heard in security and compliance discussions.
12 chapters in this module
  1. Speaking the language of control maturity
  2. Translating risk for leadership
  3. Documenting due diligence effectively
  4. Balancing mission urgency and security
  5. Escalating concerns without overstepping
  6. Collaborating with IT on shared goals
  7. Using framework alignment as leverage
  8. Demonstrating proactive oversight
  9. Aligning compliance with donor trust
  10. Creating repeatable review processes
  11. Leading without authority
  12. Building credibility through preparation
Module 6. Control Implementation for Non-IT Roles
Focuses on what advancement leaders can implement directly within their sphere.
12 chapters in this module
  1. User access reviews
  2. Password hygiene campaigns
  3. Phishing simulation participation
  4. Device encryption enforcement
  5. Software update tracking
  6. Secure file naming conventions
  7. Donor communication templates
  8. Data classification training
  9. Document retention calendars
  10. Audit trail requests
  11. Incident reporting procedures
  12. Annual control self-assessment
Module 7. Stakeholder Communication and Trust
Covers how to communicate control efforts to donors, parents, and leadership.
12 chapters in this module
  1. Explaining security to non-technical audiences
  2. Donor assurance statements
  3. Parent-facing transparency
  4. Leadership updates on control maturity
  5. Annual reports with compliance context
  6. Press response readiness
  7. Crisis communication planning
  8. Social media data policies
  9. Website privacy disclosures
  10. Vendor transparency updates
  11. Board-level messaging without jargon
  12. Reputation risk and control alignment
Module 8. Audit and Compliance Readiness
Prepares leaders to participate meaningfully in audit cycles and compliance reviews.
12 chapters in this module
  1. Understanding SOC 2 readiness
  2. Preparing for ISO 27001 alignment
  3. Responding to auditor inquiries
  4. Providing documented due diligence
  5. Reviewing control evidence
  6. Mapping processes to frameworks
  7. Identifying control gaps
  8. Remediation tracking
  9. Control ownership documentation
  10. Audit timeline expectations
  11. Internal vs external audit focus
  12. Follow-up action planning
Module 9. Data Governance in Advancement
Establishes best practices for handling donor, student, and family data across systems.
12 chapters in this module
  1. Data classification levels
  2. Consent tracking for communications
  3. Donor data retention policies
  4. Student privacy in fundraising
  5. FERPA and donor records
  6. Data minimization principles
  7. Secure sharing across departments
  8. Data subject access requests
  9. Right to be forgotten workflows
  10. Data mapping exercises
  11. Third-party data flow tracking
  12. Annual data audit preparation
Module 10. Policy Development and Adoption
Guides leaders in co-owning policy development with IT and legal teams.
12 chapters in this module
  1. Drafting acceptable use policies
  2. Remote work security standards
  3. Mobile device policies
  4. Vendor onboarding checklists
  5. Incident response playbooks
  6. Data breach notification plans
  7. Password policy enforcement
  8. Phishing response protocols
  9. Social engineering awareness
  10. Policy review cycles
  11. Training completion tracking
  12. Leadership attestation processes
Module 11. Cross-Functional Collaboration
Builds frameworks for effective partnership between advancement, IT, and compliance teams.
12 chapters in this module
  1. Joint control ownership models
  2. Monthly security sync meetings
  3. Shared KPIs for data integrity
  4. Escalation pathways
  5. Interdepartmental training
  6. Control gap action planning
  7. Vendor review committees
  8. Annual risk assessment participation
  9. Security awareness messaging
  10. Crisis simulation roles
  11. Post-mortem accountability
  12. Trust-building through consistency
Module 12. Sustaining Influence Over Time
Ensures long-term integration of security practices into advancement leadership.
12 chapters in this module
  1. Annual control maturity reviews
  2. Succession planning for oversight
  3. Documenting decision rationale
  4. Scaling practices across campuses
  5. Benchmarking against peer institutions
  6. Continuous improvement cycles
  7. Staying current with CIS updates
  8. Incorporating feedback loops
  9. Measuring influence growth
  10. Sharing wins across leadership
  11. Mentoring future leaders
  12. Building a legacy of trust

How this maps to your situation

  • When evaluating new donor platforms
  • Before signing a SaaS contract
  • During annual compliance reviews
  • After a security incident

Before vs. after

Before
Invited to vendor discussions but lacking a structured way to contribute or challenge assumptions.
After
Regularly shapes decisions with framework-backed reasoning and documented due diligence.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3-4 hours per module, designed for busy practitioners to complete in short sessions.

If nothing changes
Without a clear framework, advancement leaders risk being sidelined in key decisions that impact donor trust and institutional reputation.

How this compares to the alternatives

Unlike generic compliance courses, this program is tailored to advancement leaders in mission-driven institutions and grounded in the CIS Controls framework adopted by peer organizations.

Frequently asked

Is this course technical?
No. It’s designed for non-technical leaders who need to influence technical decisions with authority and clarity.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me in vendor negotiations?
Yes. You’ll gain a structured way to assess security and compliance in SaaS platforms used by advancement teams.
$199 one-time. Approximately 3-4 hours per module, designed for busy practitioners to complete in short sessions..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours