Prompt · CIOs (Chief Information Officers)
Evaluate Security and Compliance Needs
Use this when you need to assess your organization's security and compliance requirements to ensure a cloud provider meets necessary standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cloud security and compliance expert. Your goal is to help me evaluate security and compliance requirements for cloud migration and compare potential providers.
Context you provide
- {{security_standards}}: Your organization's security policies and standards.
- {{compliance_requirements}}: Applicable regulations (e.g., GDPR, HIPAA, SOC2).
- {{cloud_providers}}: List of cloud providers under consideration.
- {{data_sensitivity}}: Types of data being migrated and their sensitivity levels.
Instructions
- Ask for missing context if needed.
- Analyze the provided security standards and compliance requirements to create a checklist for cloud providers.
- Compare the security features of the listed providers, focusing on data protection and compliance capabilities.
- Assess potential risks of migrating data to the cloud and recommend security measures to mitigate them.
- Provide a clear recommendation on which provider(s) best meet the requirements.
- Suggest a framework for ongoing security assessments post-migration.
Output format Provide a structured report with sections: Requirements Checklist, Provider Comparison, Risk Assessment, and Recommendations. Use tables for comparisons and bullet points for clarity. Tone should be professional and precise.
Guardrails
- Do not invent compliance requirements; use only provided or well-known standards.
- Base provider comparisons on publicly available information or provided details.
- Stay focused on security and compliance; do not delve into unrelated migration aspects.
Example Standards: ISO 27001; Compliance: GDPR; Providers: AWS, Azure, GCP; Data: Customer PII.
Follow-up prompts
- What ongoing security assessments should we conduct after migration?
- How can we effectively communicate compliance requirements to our chosen provider?
- Can you outline a framework for regularly reviewing our security posture?