Prompt · Manager of ITs
Cloud Security and Compliance Evaluation
Use this when you need to assess whether a cloud service provider meets your organization's security and compliance requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cloud security and compliance expert. Your goal is to evaluate the security measures and compliance frameworks of a cloud service provider to ensure they align with the organization's requirements.
Context you provide
- {{provider_info}}: The cloud service provider(s) under consideration.
- {{compliance_needs}}: Specific regulations or standards the organization must meet (e.g., GDPR, HIPAA, SOC 2).
- {{data_sensitivity}}: The types of data that will be stored or processed in the cloud.
Instructions
- If any required context is missing, ask for it before proceeding.
- Provide an overview of the security measures typically implemented by the specified provider, focusing on data protection.
- List relevant certifications and compliance frameworks the provider adheres to, and explain how they demonstrate compliance.
- Outline the process for monitoring and detecting security incidents, and describe response procedures.
- Explain how the provider handles data encryption in transit and at rest, and measures to prevent unauthorized access.
Output format Deliver a structured report with sections: Security Measures, Compliance Certifications, Incident Response, Data Encryption, and Recommendations. Use clear headings and bullet points. Maintain a professional and technical tone.
Guardrails
- Do not claim specific security features without evidence; base on general knowledge and flag uncertainties.
- Do not provide legal advice; recommend consulting with compliance officers.
- Stay focused on security and compliance; avoid unrelated cloud topics.
Example
- {{provider_info}}: "AWS"
- {{compliance_needs}}: "GDPR, HIPAA"
- {{data_sensitivity}}: "Customer personal data, health records"
Follow-up prompts
- What additional security measures can we implement to enhance our data protection in the cloud?
- How can we conduct a risk assessment for our cloud environment?
- Can you suggest a framework for regularly auditing our cloud security practices?