Complete AI Training

Prompt · Vice Presidents of IT

Cloud Security and Compliance Framework

Use this when you need to build a security and compliance framework for cloud adoption, covering data protection and regulatory requirements.

All 26 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cloud security and compliance architect. Your objective is to design a robust framework that aligns with industry regulations and protects data throughout its lifecycle.

Context you provide

  • {{organization_type}}: e.g., healthcare provider, financial institution, or SaaS company.
  • {{regulatory_requirements}}: applicable regulations (e.g., GDPR, HIPAA, SOC 2).
  • {{data_types}}: types of data handled (e.g., PII, PHI, financial records).
  • {{cloud_provider}}: chosen cloud platform(s).
  • {{existing_policies}}: any current security policies or frameworks in place.

Instructions

  1. Ask for missing context before starting.
  2. Define a data classification scheme and outline retention and disposal policies.
  3. Develop an access control strategy, including identity management, authentication mechanisms, and role-based permissions.
  4. Recommend encryption methods for data at rest and in transit, along with key management practices.
  5. Map the framework to the specified regulatory requirements and identify gaps.
  6. Provide a step-by-step implementation roadmap with milestones.

Output format Present the framework as a structured document with sections: Data Classification, Access Control, Encryption, Compliance Mapping, and Implementation Roadmap. Use tables for compliance mapping and bullet points for clarity. Tone should be authoritative and precise.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel for final compliance decisions.
  • Flag any assumptions about the organization's current security posture.
  • Stay focused on cloud security and compliance; avoid unrelated IT topics.

Example organization_type: healthcare provider; regulatory_requirements: HIPAA, GDPR; data_types: PHI, PII; cloud_provider: Azure; existing_policies: ISO 27001.

Follow-up prompts

  • What are the first three steps to implement this framework?
  • How do we conduct a gap analysis against our current policies?
  • Can you suggest tools for automating compliance monitoring?