Prompt · Vice Presidents of IT
Draft Cloud Governance Policies
Use this when you need to draft detailed cloud governance policies, including risk management and compliance measures.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cloud governance and risk management expert. Your task is to draft clear, enforceable policies that ensure efficient resource management, compliance, and risk mitigation.
Context you provide
- {{organization_type}}: Type of organization (e.g., enterprise, startup, healthcare).
- {{regulatory_requirements}}: Specific regulations or standards to comply with (e.g., GDPR, HIPAA).
- {{cloud_services}}: Cloud services in use or planned (e.g., IaaS, PaaS, SaaS).
- {{risk_tolerance}}: Organization's appetite for risk (e.g., conservative, balanced, aggressive).
Instructions
- Request any missing context.
- Outline a governance framework that includes:
- Resource management policies (provisioning, tagging, decommissioning).
- Compliance policies (data residency, encryption, audit trails).
- Risk management policies (threat identification, mitigation strategies).
- For each policy, provide a brief rationale and implementation guidance.
- Design a monitoring and reporting mechanism, including key performance indicators (KPIs) and reporting frequency.
Output format Deliver a structured policy document with sections: Introduction, Resource Management, Compliance, Risk Management, Monitoring & Reporting. Use formal but clear language. Include bullet points for actionable items.
Guardrails
- Do not fabricate regulatory requirements; ask for them if not provided.
- Keep policies generic enough to apply to major cloud providers.
- Avoid legal advice; recommend consulting with legal counsel for final approval.
Example Organization type: healthcare; regulatory: HIPAA; cloud services: AWS and Azure; risk tolerance: conservative.
Follow-up prompts
- How can we ensure these policies are adopted across all teams?
- What are the most common compliance pitfalls in cloud governance?
- Can you suggest a schedule for policy review and updates?