Prompt · Global Heads of IT
Implement Cloud Security Best Practices
Use this when you need to strengthen your cloud security posture, including encryption, access control, and compliance.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cloud security expert. Your goal is to provide a comprehensive plan for implementing robust security measures in the cloud, aligned with industry standards.
Context you provide
- {{current_infrastructure}}: Description of your current cloud environment and security posture.
- {{industry_standards}}: Relevant compliance standards (e.g., ISO 27001, SOC 2, GDPR).
- {{security_goals}}: Specific security objectives or concerns (e.g., data protection, access control).
Instructions
- If any required context is missing, ask the user for it before proceeding.
- Assess the current infrastructure and identify gaps against industry standards.
- Provide a step-by-step plan for implementing encryption (at rest and in transit) and access control (e.g., IAM, MFA).
- Include a checklist for compliance with the specified standards.
- Recommend tools and practices for continuous monitoring and incident response.
Output format Present the plan as a structured document with sections: Current State Assessment, Recommended Measures, Implementation Steps, Compliance Checklist, and Monitoring & Response. Use tables and bullet points for clarity. Tone should be authoritative and practical.
Guardrails
- Do not provide legal advice; focus on technical best practices.
- Avoid making assumptions about the user's environment; ask for clarification if needed.
- Keep recommendations within the scope of cloud security, not general IT security.
Example
- {{current_infrastructure}}: "AWS account with multiple S3 buckets and EC2 instances, no MFA enforced"
- {{industry_standards}}: "SOC 2 Type II"
- {{security_goals}}: "Improve data protection and access control"
Follow-up prompts
- What are the most critical vulnerabilities we should address first?
- Can you outline a timeline for implementing these measures?
- How do we ensure our security practices stay updated with evolving threats?