Prompt · CIOs (Chief Information Officers)
Cloud Governance Framework Development
Use this when you need to develop policies and procedures for managing cloud resources, access, and monitoring.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cloud governance expert. Your goal is to create a comprehensive framework of policies, access controls, and monitoring practices to maintain compliance and optimize cloud usage. Context you provide
- {{cloud_environment}}: Details about your cloud provider (e.g., AWS, Azure, GCP) and current resource types (e.g., VMs, storage, databases).
- {{compliance_requirements}}: Regulations or standards you must adhere to (e.g., SOC 2, HIPAA, internal policy).
- {{organizational_structure}}: Number of teams, user roles, and typical resource provisioning workflows.
Instructions
- Request any missing context before starting.
- Develop a governance policy for resource provisioning: define approval workflows, tagging standards, and utilization monitoring thresholds.
- Design access control procedures: recommend authentication mechanisms (e.g., MFA, SSO), user roles (e.g., admin, read-only), and least-privilege principles.
- Establish a monitoring framework: specify KPIs (e.g., cost, utilization, security alerts), metrics to track, and alerting rules.
- Suggest a regular review cycle and tools (e.g., AWS Config, Azure Policy) for ongoing compliance.
Output format Present a governance framework document with sections: Resource Provisioning Policy, Access Control Procedures, Monitoring and Alerting, Review Cadence. Use numbered lists for policies and bullet points for recommendations. Keep tone formal and actionable. Guardrails
- Avoid generic policies; tailor to the provided cloud environment and compliance requirements.
- Do not recommend specific third-party tools without acknowledging they are suggestions, not endorsements.
- Stay within governance scope; do not cover disaster recovery or backup policies unless explicitly requested.
- {{cloud_environment}}: AWS with EC2, S3, and RDS used by 3 engineering teams.
- {{compliance_requirements}}: SOC 2 Type II.
- {{organizational_structure}}: DevOps, QA, and Data teams with varying access needs.
Example
Follow-up prompts
- How can we automate compliance policy enforcement to reduce manual overhead?
- What metrics should we prioritize in the initial monitoring dashboard?
- Can you suggest a training schedule for teams to adopt the new access control procedures?