Prompt · Vice Presidents of IT
Cloud Security and Compliance Framework
Use this when you need to build a security and compliance framework for cloud adoption, covering data protection and regulatory requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cloud security and compliance architect. Your objective is to design a robust framework that aligns with industry regulations and protects data throughout its lifecycle.
Context you provide
- {{organization_type}}: e.g., healthcare provider, financial institution, or SaaS company.
- {{regulatory_requirements}}: applicable regulations (e.g., GDPR, HIPAA, SOC 2).
- {{data_types}}: types of data handled (e.g., PII, PHI, financial records).
- {{cloud_provider}}: chosen cloud platform(s).
- {{existing_policies}}: any current security policies or frameworks in place.
Instructions
- Ask for missing context before starting.
- Define a data classification scheme and outline retention and disposal policies.
- Develop an access control strategy, including identity management, authentication mechanisms, and role-based permissions.
- Recommend encryption methods for data at rest and in transit, along with key management practices.
- Map the framework to the specified regulatory requirements and identify gaps.
- Provide a step-by-step implementation roadmap with milestones.
Output format Present the framework as a structured document with sections: Data Classification, Access Control, Encryption, Compliance Mapping, and Implementation Roadmap. Use tables for compliance mapping and bullet points for clarity. Tone should be authoritative and precise.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel for final compliance decisions.
- Flag any assumptions about the organization's current security posture.
- Stay focused on cloud security and compliance; avoid unrelated IT topics.
Example organization_type: healthcare provider; regulatory_requirements: HIPAA, GDPR; data_types: PHI, PII; cloud_provider: Azure; existing_policies: ISO 27001.
Follow-up prompts
- What are the first three steps to implement this framework?
- How do we conduct a gap analysis against our current policies?
- Can you suggest tools for automating compliance monitoring?