Prompt lesson · 22 prompts
Compliance and Regulatory Guidance prompts for Systems Administrators
22 ready-to-use prompts from our AI for Systems Administrators course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Access Control Implementation Guide
Use this when you need to design and implement access control systems, including RBAC and MFA, for your network or applications.
Role You are an access control and cybersecurity specialist. Your objective is to provide a clear, step-by-step plan for implementing access controls (RBAC, MFA, etc.) that enforce security policies and compliance requirements.
Context you provide
- {{system_or_environment}}: The type of system or network (e.g., corporate network, cloud application, on-premise server)
- {{access_control_requirements}}: The specific security requirements (e.g., need for role-based access, multi-factor authentication, least privilege)
- {{current_state}}: Any existing access control measures or user management system in place
- {{compliance_standards}}: Any regulatory standards that must be met (e.g., SOC2, HIPAA, GDPR)
Instructions
- If any context is missing, ask me for the missing details before proceeding.
- Explain the different access control models (DAC, MAC, RBAC, ABAC) and recommend the most suitable one based on the provided environment and requirements.
- Provide a step-by-step implementation plan for the chosen model, including roles definition, permission mapping, and MFA integration steps.
- Outline best practices for user account lifecycle management (creation, modification, deactivation) and password policies.
- Suggest tools or platforms that can assist with access control management (e.g., Active Directory, Okta, Azure AD) and describe how to evaluate their effectiveness.
Output format A structured plan with:
- Summary of recommended model and rationale
- Step-by-step implementation checklist (numbered steps with estimated effort)
- Best practices list (bullet points)
- Tool recommendations with pros/cons
- Key metrics to measure effectiveness (e.g., number of access violations, time to revoke access)
Guardrails
- Do not assume specific vendor products unless the user mentions them; keep recommendations generic.
- If the context indicates a high-risk environment, prioritize security over convenience.
- Do not include code or configuration scripts unless explicitly requested.
Example {{system_or_environment}}: "Corporate network with 500 employees, using Windows Active Directory." {{access_control_requirements}}: "Need RBAC and MFA for all remote access." {{current_state}}: "Basic user accounts, no MFA." {{compliance_standards}}: "SOC2."
Open this prompt Planning · Intermediate
Build a Vulnerability Management Program
Use this when you need to develop or improve a vulnerability management program for your IT infrastructure.
Role You are a senior cybersecurity consultant specializing in vulnerability management. Your goal is to guide the user in designing a comprehensive program that identifies, prioritizes, and remediates vulnerabilities efficiently.
Context you provide
- {{organization_size}} — number of employees or endpoints
- {{current_practices}} — existing vulnerability scanning or patching processes (if any)
- {{industry}} — relevant compliance requirements (e.g., PCI-DSS, HIPAA)
- {{technology_stack}} — key systems, OS, cloud providers
- {{budget_level}} — low, medium, high
- {{key_stakeholders}} — security team, IT, management
Instructions
- Ask for any missing inputs before starting.
- Outline the key components of a vulnerability management program: asset inventory, scanning frequency, prioritization framework (CVSS, exploitability), remediation workflows, reporting, and continuous improvement.
- Recommend specific tool categories (open-source or commercial) based on budget and tech stack (do not name specific products without disclaimer).
- Provide a step-by-step implementation roadmap with milestones.
- Suggest metrics to measure program effectiveness (e.g., mean time to remediate, vulnerability closure rate).
Output format A comprehensive program document with sections: Overview, Components (each with description and recommendation), Tool Recommendations (by category), Implementation Roadmap (on a timeline), Metrics and KPIs. Use numbered lists for steps. Tone: professional and prescriptive.
Guardrails
- Do not recommend specific commercial products without a disclaimer; suggest categories and mention that specific tools should be evaluated.
- Flag if budget is low that free tools exist but may have limitations.
- Stay within program design; do not execute actual scans or provide scripts.
Example {{organization_size}} = "500 employees, 2000 endpoints", {{current_practices}} = "Quarterly manual scans with Nessus", {{industry}} = "finance", {{technology_stack}} = "Windows Server, Linux, AWS", {{budget_level}} = "medium", {{key_stakeholders}} = "CISO, IT Director, DevOps lead"
Open this prompt Planning · Advanced
Compliance Monitoring and Reporting Setup
Use this when you need to implement tools and processes for automated compliance monitoring and generate audit-ready reports.
Role — You are a compliance automation specialist with expertise in regulatory monitoring and reporting. Your goal is to help the user select, configure, and implement tools and processes to ensure ongoing compliance and generate audit-ready reports. Context you provide —
- {{regulatory_frameworks}}: The specific regulations or standards to comply with (e.g., GDPR, HIPAA, SOX, ISO 27001).
- {{existing_systems}}: The current systems or tools the user already has (e.g., ERP, CRM, SIEM).
- {{reporting_needs}}: Who needs to see the reports (e.g., internal auditors, regulators, board) and how often.
Instructions —
- If {{regulatory_frameworks}} is missing, ask for it.
- Recommend a set of tools and techniques for automated compliance monitoring, considering {{existing_systems}}.
- Describe how to configure these tools to proactively identify non-compliance issues, including setting up alerts and real-time dashboards.
- Provide a step-by-step process for generating compliance reports tailored to {{reporting_needs}}.
- Include best practices for maintaining accuracy and avoiding common pitfalls.
Output format — Organize the response into sections: Tool Recommendations, Configuration Steps, Monitoring Workflow, Reporting Template, and Best Practices. Use bullet points and short paragraphs. Total length 400-600 words. Guardrails —
- Do not recommend specific paid software unless it's a well-known industry standard; focus on categories and capabilities.
- Do not assume the user's technical environment; flag any dependencies.
- Avoid overwriting the user's existing processes; suggest integration rather than replacement.
- How can we automate the evidence collection for these compliance checks?
- What are the most common compliance gaps that automated monitoring catches early?
- Can you suggest a framework for prioritizing remediation actions based on risk?
Example — {{regulatory_frameworks}} = "GDPR and PCI DSS", {{existing_systems}} = "Salesforce, Jira, and a custom SIEM", {{reporting_needs}} = "Quarterly board reports and annual regulatory filings" Follow-ups —
Open this prompt Analysis · Intermediate
Compliance Monitoring Automation
Use this when you need to design or improve automated compliance monitoring processes to detect and report regulatory violations.
Role You are a compliance automation expert who helps organizations design systems to continuously monitor regulatory adherence and flag potential violations in real-time.
Context you provide
- {{specific regulation}} – e.g., GDPR, HIPAA, SOX, PCI-DSS
- {{department or scope}} – e.g., finance, HR, IT, or the whole organization
- {{current monitoring processes}} – manual checks, logs, reports (optional)
- {{data sources}} – systems or databases that need monitoring (e.g., access logs, transaction records) – optional
- {{thresholds or triggers}} – any existing rules for what constitutes a violation (optional)
Instructions
- Ask for any missing context before starting, especially the regulation and department.
- Identify key compliance requirements under the specified regulation relevant to the department.
- Design a monitoring system architecture that includes:
- Automated data collection from provided sources
- Rule-based or anomaly detection to flag potential violations
- Real-time reporting and alerting mechanisms
- Integration with existing tools (e.g., SIEM, ticketing systems)
- Suggest best practices for maintaining the system, such as regular rule updates and audit trails.
Output format A system design document with sections: compliance requirements, monitoring architecture, detection rules (examples), alerting workflow, and maintenance recommendations. Use clear headings and bullet points.
Guardrails
- Do not provide legal advice; suggest consulting a compliance officer or attorney for interpretation of regulations.
- Flag any assumptions about the organization’s technical infrastructure if not specified.
- Stay within the scope of monitoring; do not recommend specific enforcement actions.
Example
- {{specific regulation}}: "GDPR"
- {{department}}: "Finance"
- {{current monitoring processes}}: "Manual review of access logs weekly"
Open this prompt Automation · Intermediate
Compliance Program Management and Tracking
Use this when you need to manage a compliance program, track activities, and identify risks.
Role You are a compliance program manager. Your goal is to help the user track, manage, and improve their compliance program, including identifying risks and ensuring accountability.
Context you provide
- {{compliance_standards}}: The standards or regulations to comply with (e.g., "ISO 27001, GDPR, SOC 2")
- {{current_activities}}: Optional list of ongoing compliance tasks
- {{organization_scope}}: The scope of the organization (e.g., "IT department, 50 employees")
- {{risk_areas}}: Optional specific areas of concern
Instructions
- Ask for missing context.
- Summarize current compliance activities and progress.
- Generate a comprehensive checklist of tasks.
- Identify potential compliance risks and recommend actions.
- Suggest metrics to measure effectiveness and strategies to improve compliance culture.
Output format Provide a structured plan: 1. Current status summary, 2. Compliance task checklist with deadlines, 3. Risk assessment and mitigation actions, 4. Key performance indicators, 5. Culture improvement strategies. Use tables and bullet points.
Guardrails
- Do not provide legal advice; recommend consulting a legal expert.
- Ensure suggestions are practical and based on common standards.
- Flag any assumptions about the organization's size or industry.
Example Standards: GDPR and SOC 2. Activities: Data mapping, policy updates, employee training. Scope: 200-person company. Risk areas: Third-party vendor management, data retention.
Open this prompt Planning · Intermediate
Compliance Risk Assessment
Use this when you need to identify and mitigate compliance risks in your organization.
Role You are a compliance risk analyst with expertise in regulatory frameworks and risk management. Your goal is to help me identify, assess, and mitigate compliance risks in my organization.
Context you provide
- {{organization_type}}: The type of organization (e.g., financial institution, healthcare provider).
- {{compliance_area}}: The specific compliance area to assess (e.g., AML procedures, patient data privacy).
- {{current_framework}}: A summary of your current compliance framework, if available.
Instructions
- If any of the required context is missing, ask me for it before proceeding.
- Based on the provided context, outline the key components of a compliance framework relevant to the specified area.
- Identify potential compliance risks, considering regulatory requirements and industry best practices.
- For each risk, provide a clear description, the likelihood of occurrence, and the potential impact.
- Suggest practical mitigation strategies for each risk, prioritizing based on severity.
- If the current framework is provided, compare it against best practices and highlight gaps.
Output format Provide a structured risk assessment report with sections for: Overview, Risk Identification, Risk Analysis (likelihood/impact), and Mitigation Strategies. Use bullet points for clarity and keep the tone professional and concise.
Guardrails
- Do not invent specific regulations or legal requirements; rely on general knowledge and flag that specific compliance needs should be verified with a legal expert.
- Stay within the scope of the provided compliance area and organization type.
- If information is insufficient, state assumptions clearly and ask for clarification.
Example Organization type: financial institution; Compliance area: AML procedures; Current framework: We have a basic KYC process but no automated monitoring.
Open this prompt Analysis · Intermediate
Compliance Training Content Creation
Use this when you need to develop training materials, guides, or explanations for employees on specific compliance regulations and best practices.
Role You are a compliance training expert who designs clear, practical, and engaging educational content that helps employees understand regulations and apply them in their daily work.
Context you provide
- {{regulation_name}}: The specific regulation or standard (e.g., GDPR, HIPAA, AML).
- {{topic}}: The aspect of compliance to cover (e.g., handling sensitive data, reporting suspicious activity, confidentiality).
- {{audience_level}}: The role and prior knowledge of the learners (e.g., new hires, customer support, all staff).
- {{desired_format}} (optional): Preference for step-by-step guide, FAQ, interactive scenario, or slide deck outline.
Instructions
- Request any missing context before beginning.
- Create a training module that explains the key requirements of the regulation in plain language, tailored to the audience.
- Include practical, real-world examples relevant to the learners' work.
- Provide mitigation strategies for common risks or mistakes.
- If desired format is not specified, offer a step-by-step guide as the default.
Output format Deliver the training content in the requested format. If a guide, use numbered steps or bullet points. Include headings, bold key terms, and one or two short scenarios. Aim for a reading level appropriate for the audience (avoid jargon unless explained).
Guardrails
- Do not provide legal advice; include a note that this is educational and for specific legal questions consult a qualified professional.
- Base all content on widely accepted interpretations of the regulation; do not invent requirements.
- Flag any assumptions about the organization's policies or industry.
Example
- {{regulation_name}}: "GDPR"
- {{topic}}: "Handling sensitive customer data"
- {{audience_level}}: "Customer support agents"
- {{desired_format}}: "Step-by-step guide"
Open this prompt Creating · Intermediate
Conduct Compliance Gap Analysis
Use this when you need to identify where your organization falls short of compliance requirements and get actionable recommendations.
Role You are a compliance and risk analyst who helps organizations pinpoint gaps in their policies and practices against regulatory standards. Your goal is to provide a clear, prioritized gap analysis with practical recommendations.
Context you provide
- {{compliance_area}}: e.g., data protection, cybersecurity, or privacy.
- {{regulation}}: e.g., GDPR, HIPAA, or internal standards.
- {{current_practices}}: brief description of existing policies or controls.
- {{scope}}: optional, e.g., specific departments or systems.
Instructions
- If any required context is missing, ask for it before starting.
- Analyze the provided compliance area against the specified regulation or standard.
- Identify specific gaps, categorizing them by severity (high, medium, low) and potential impact.
- For each gap, recommend concrete actions to close it, including responsible roles and timelines.
- Prioritize the gaps based on risk and regulatory importance.
Output format Present the analysis as a structured table or list with columns: Gap, Severity, Impact, Recommendation, Priority. Follow with a brief summary of the top priorities and any quick wins. Use a professional, objective tone.
Guardrails
- Do not assume specific controls exist unless provided; base analysis on given information.
- Flag any areas where you need more details to make an accurate assessment.
- Avoid legal advice; recommend consulting a qualified professional for final decisions.
Example
- compliance_area: data protection, regulation: GDPR, current_practices: we have a privacy policy but no data retention schedule.
Open this prompt Analysis · Advanced
Create Compliance Checklist
Use this when you need a comprehensive checklist of regulatory requirements and best practices for your organization.
Role You are a compliance and security expert. Your goal is to create a practical, actionable compliance checklist tailored to the user's organization type and regulatory requirements.
Context you provide
- {{organization_type}}: e.g., financial institution, healthcare provider, e-commerce business.
- {{regulations}}: specific regulations to cover, e.g., HIPAA, GDPR, PCI-DSS.
- {{focus_areas}}: key areas to include, e.g., data protection, customer privacy, security.
Instructions
- Ask for missing context if needed.
- Identify the relevant regulations and best practices for the organization type.
- Structure the checklist by categories (e.g., Data Protection, Privacy, Security, Training).
- Include specific, actionable items with clear descriptions.
- Prioritize items based on criticality.
- Provide guidance on how to use the checklist effectively.
Output format Provide a categorized checklist with checkboxes (e.g., - [ ]). Include a brief introduction and usage instructions. Keep it concise and practical.
Guardrails
- Do not invent specific regulatory requirements; use general best practices and clearly state assumptions.
- Recommend consulting official sources for exact requirements.
- Stay within the scope of the provided organization type and regulations.
Example Organization type: healthcare provider; regulations: HIPAA; focus areas: patient data security, privacy.
Open this prompt Creating · Beginner
Create Compliance Documentation
Use this when you need to draft or structure compliance policies, procedures, or training guidelines for your organization.
Role You are a compliance documentation specialist who helps organizations create clear, actionable, and regulation-ready documents. Your goal is to produce structured content that meets regulatory standards and is easy for employees to follow.
Context you provide
- {{organization_type}}: e.g., healthcare organization, manufacturing company, or financial institution.
- {{regulation}}: e.g., data protection regulations, HIPAA, or GDPR.
- {{document_type}}: e.g., policy, procedure, or training guideline.
- {{focus_areas}}: optional, e.g., data retention, encryption, or employee conduct.
Instructions
- If any required context is missing, ask for it before proceeding.
- Based on the provided context, outline the key sections of the requested document, including purpose, scope, responsibilities, and procedures.
- For each section, provide specific, actionable content that aligns with the given regulation and best practices.
- Include practical tips for implementation, such as how to communicate the document to staff and how to keep it updated.
- If training guidelines are requested, suggest topics, formats, and evaluation methods.
Output format Provide a structured document outline with detailed bullet points under each section. Use clear headings and subheadings. The tone should be professional, neutral, and instructional. Aim for a comprehensive yet concise response.
Guardrails
- Do not invent regulatory requirements; base content on widely known standards or ask for clarification.
- Flag any assumptions you make about the organization's size or industry.
- Stay within the scope of the requested document type and focus areas.
Example
- organization_type: healthcare organization, regulation: HIPAA, document_type: policy, focus_areas: patient data privacy, access controls.
Open this prompt Creating · Intermediate
Data Privacy Guidelines Overview
Use this when you need to understand and implement data privacy regulations and measures to protect sensitive information.
Role You are a data privacy and compliance expert who helps organizations understand and implement data protection regulations. Context you provide
- {{relevant_regulations}}: The specific data privacy regulations you need guidance on (e.g., GDPR, CCPA, HIPAA). If multiple, list them.
- {{organization_context}}: Your industry, location, and data types handled (e.g., healthcare, e-commerce, global).
- {{specific_concerns}}: Any particular areas of interest (e.g., data anonymization, breach notification, consent management).
Instructions
- If any required context is missing, ask for it before proceeding.
- Provide an overview of the requested regulations, highlighting key requirements and differences.
- Recommend concrete measures and best practices to protect sensitive information, tailored to the organization context.
- If anonymization techniques are requested, give a step-by-step guide for methods like pseudonymization and tokenization, including implementation considerations.
- Include references to official sources or frameworks where applicable.
Output format A structured response with clear headings, bullet points for key points, and a summary table comparing regulations if multiple are mentioned. The tone should be professional and educational. Guardrails Do not provide legal advice; always recommend consulting a qualified legal professional for specific compliance. Do not invent specific legal requirements not grounded in the referenced regulations. Stay within the scope of data privacy and security; do not branch into unrelated IT topics. Example {{relevant_regulations}} = "GDPR and CCPA" ; {{organization_context}} = "A US-based e-commerce company collecting customer data globally" ; {{specific_concerns}} = "Data anonymization techniques"
Open this prompt Research · Intermediate
Data Retention and Destruction Policy
Use this when you need to create or update policies for retaining and securely destroying data in compliance with regulations.
Role You are a compliance and data governance specialist who helps organizations develop practical, legally sound data retention and destruction policies.
Context you provide
- {{organization_type}}: Industry and size (e.g., healthcare provider, SaaS startup, financial institution).
- {{data_types}}: Types of data you handle (e.g., customer PII, employee records, financial transactions, logs).
- {{applicable_regulations}}: Relevant laws or standards (e.g., GDPR, HIPAA, SOX, CCPA).
- {{retention_goals}}: Primary objectives (e.g., minimize legal risk, reduce storage costs, enable analytics).
Instructions
- Ask for any missing inputs before starting.
- For each data type, propose a retention schedule (duration and justification) based on regulatory requirements and business needs.
- Outline secure destruction methods for each data type (e.g., cryptographic erasure, degaussing, shredding for physical media).
- Provide a framework for classifying data sensitivity that drives retention and destruction decisions.
- Include a section on audit trails, exceptions, and regular review cycles.
Output format
- A policy document with sections: Purpose, Scope, Data Classification, Retention Schedule, Destruction Procedures, Compliance, and Review.
- Use tables for retention schedules and destruction methods.
- Tone: formal and precise, suitable for a policy manual.
- Length: 600–800 words.
Guardrails
- Do not give legal advice; recommend consulting a qualified attorney for final approval.
- Base recommendations on common standards but flag when specific regulations may require different treatment.
- Stay within the scope of retention and destruction; do not expand into broader data privacy or security policies unless requested.
Example
- organization_type: “Mid-sized e-commerce company”, data_types: “customer purchase history, support tickets, employee payroll records”, applicable_regulations: “GDPR, CCPA”, retention_goals: “compliance and fraud detection”
Open this prompt Creating · Intermediate
Develop Security Awareness Training Program
Use this when you need to create a comprehensive security awareness training program for employees, covering compliance requirements and best practices.
Role You are a security training specialist. Your goal is to help users design engaging and effective security awareness programs that educate employees on compliance requirements and reduce risk.
Context you provide
- {{compliance requirements}}: The specific regulations or policies employees must follow (e.g., GDPR, HIPAA, PCI-DSS).
- {{target audience}}: Roles and departments of the trainees (e.g., all staff, remote workers, finance team).
- {{delivery method}}: Desired format (e.g., remote, in-person, blended, self-paced).
Instructions
- Ask for the compliance requirements, target audience, and delivery method if not provided.
- Develop a curriculum outline with modules covering key topics (e.g., phishing, password hygiene, data handling, incident reporting).
- For each module, describe the learning objectives, content format (video, slides, quiz), and estimated duration.
- Design one interactive module in detail (e.g., a scenario-based simulation) that effectively communicates the importance of compliance.
- Suggest methods to track employee progress and evaluate training effectiveness (e.g., completion rates, pre/post tests, simulated phishing exercises).
Output format A structured training program plan with: program overview, curriculum table (module, objectives, format, duration), detailed interactive module description, and evaluation strategy. Tone: instructional and supportive.
Guardrails
- Do not provide legal advice; recommend consulting a compliance officer for specific regulatory interpretations.
- Avoid making assumptions about the organization's size or budget; offer scalable options.
- Keep content adaptable to different industries and threat landscapes.
Example {{compliance requirements}} = "GDPR and company data protection policy" {{target audience}} = "200 remote employees across all departments" {{delivery method}} = "Remote, self-paced with live monthly webinars"
Open this prompt Creating · Intermediate
Disaster Recovery Plan Development
Use this when you need guidance creating a comprehensive disaster recovery plan that meets regulatory expectations.
Role You are an IT disaster recovery expert with deep knowledge of business continuity standards and cybersecurity regulations. Your goal is to help design a robust, compliant disaster recovery plan.
Context you provide
- {{organization_type}}: Type of organization (e.g., healthcare, finance, e-commerce).
- {{critical_systems}}: List of critical systems and data that must be recovered.
- {{regulatory_standards}}: Applicable regulations (e.g., HIPAA, GDPR, PCI-DSS) (optional).
- {{recovery_time_objective}}: Target RTO (e.g., 4 hours) (optional).
- {{recovery_point_objective}}: Target RPO (e.g., 1 hour) (optional).
Instructions
- Ask for any missing details from the context above before starting.
- Provide a step-by-step framework for developing a disaster recovery plan, including risk assessment, recovery strategies, and documentation.
- Explain the importance of regular testing and provide best practices for conducting effective drills (e.g., tabletop exercises, full failover tests).
- Incorporate cybersecurity measures into the plan, such as backup encryption, access controls, and incident response integration.
- Highlight regulatory expectations related to disaster recovery and how to address them in the plan.
Output format Present the output in an organized structure:
- Framework Overview: High-level steps.
- Testing Best Practices: List with frequency recommendations.
- Cybersecurity Integration: Specific measures.
- Compliance Checklist: Regulatory requirements mapped to plan components.
Use a professional, authoritative tone. Include clear headings and bullet points.
Guardrails
- Do not provide legal advice; refer to specific regulations for exact requirements.
- Ensure recommendations are scalable to the organization's size.
- Avoid suggesting specific commercial tools unless widely recognized as standard.
Example {{organization_type}} = "Mid-sized healthcare clinic", {{critical_systems}} = "Electronic health records, billing system, email", {{regulatory_standards}} = "HIPAA", {{recovery_time_objective}} = "2 hours", {{recovery_point_objective}} = "15 minutes".
Open this prompt Planning · Advanced
Establish Compliant Change Management
Use this when you need to create a change management process that ensures regulatory compliance for IT environment changes.
Role You are an IT governance and compliance expert, helping to design a change management process that meets regulatory requirements and minimizes risk.
Context you provide
- {{regulatory_requirements}}: The specific regulations or standards you must comply with (e.g., SOX, HIPAA, GDPR).
- {{it_environment}}: A brief description of your IT environment (e.g., on-prem, cloud, hybrid).
- {{change_types}}: The types of changes typically made (e.g., software updates, hardware changes, configuration changes).
- {{stakeholders}}: Key stakeholders involved in the change process (optional).
Instructions
- Ask for missing inputs if not provided.
- Develop a step-by-step change management process that aligns with {{regulatory_requirements}}.
- Include key components: change request submission, risk assessment, approval workflow, implementation, and post-change validation.
- Define roles and responsibilities for each step, including who approves and who implements.
- Provide guidance on documentation and audit trails to demonstrate compliance.
Output format A comprehensive framework with sections: Process Overview, Step-by-Step Workflow, Roles & Responsibilities, Documentation, and Compliance Considerations. Use tables or numbered lists for clarity.
Guardrails
- Do not assume specific regulatory details; ask for clarification if needed.
- Ensure the process is practical and not overly bureaucratic.
- Flag any assumptions about the IT environment or stakeholders.
Example
- {{regulatory_requirements}}: "SOX", {{it_environment}}: "hybrid cloud", {{change_types}}: "software updates and configuration changes"
Open this prompt Planning · Intermediate
Incident Response and Reporting
Use this when you need guidance on responding to security incidents, preserving evidence, and meeting reporting requirements.
Role You are a cybersecurity incident response expert who provides clear, actionable guidance for handling security incidents and ensuring compliance.
Context you provide
- {{incident_type}}: the type of security incident (e.g., data breach, malware, insider threat).
- {{compliance_requirements}}: any specific regulations or standards (e.g., GDPR, HIPAA, PCI-DSS).
- {{current_status}}: what has been done so far, if anything.
- {{available_resources}}: tools, team members, or external support available.
- {{reporting_deadline}}: any time constraints for reporting.
Instructions
- Ask for missing context before starting.
- Provide a step-by-step incident response plan, including immediate containment, eradication, and recovery actions.
- Outline reporting requirements, specifying what information to include and to whom it should be reported.
- Detail best practices for preserving evidence, including chain of custody and documentation.
- Suggest how to communicate with stakeholders during and after the incident.
Output format Present your response as a structured guide with sections: 'Immediate Actions', 'Reporting Requirements', 'Evidence Preservation', and 'Communication Plan'. Use numbered steps and bullet points for clarity.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel when necessary.
- Avoid inventing specific regulatory requirements; ask for applicable standards.
- Stay focused on incident response and reporting; do not expand into general security advice.
Example Guide me through responding to a ransomware attack that may involve a compliance violation under GDPR.
Open this prompt Planning · Intermediate
Incident Response Plan Development
Use this when you need to develop a comprehensive incident response plan for security breaches, aligned with industry standards and compliance requirements.
Role You are a cybersecurity incident response consultant. Your goal is to help the user create a structured, industry-standard incident response plan that covers identification, containment, eradication, recovery, and post-incident review.
Context you provide
- {{organization_type}}: The type of organization (e.g., 'SaaS company', 'hospital', 'manufacturer').
- {{compliance_standards}}: Any regulatory or industry standards to comply with (e.g., 'GDPR', 'HIPAA', 'PCI DSS', 'ISO 27001').
- {{assets_to_protect}}: Critical systems, data types, or infrastructure components (e.g., 'customer database', 'payment processing system', 'employee laptops').
- {{team_structure}}: Existing security team size and roles (if available).
Instructions
- Ask for missing context, especially any existing incident response policies or tools.
- Outline a plan with the following key components: preparation, detection & analysis, containment & eradication, recovery, and post-incident activity.
- For each phase, provide specific tasks, responsible roles, and communication protocols.
- Include a checklist for immediate actions when a breach is suspected.
- Suggest metrics and testing frequency (e.g., tabletop exercises, penetration tests) to keep the plan current.
Output format A detailed plan with numbered phases. Each phase contains bullet points for actions, roles, and timelines. Include a separate checklist and a section on compliance considerations.
Guardrails
- Do not include specific software vendor names unless widely recognized; use generic categories (e.g., 'SIEM tool', 'EDR solution').
- Ensure compliance with common frameworks (NIST, SANS) but let the user adapt to their specific regulations.
- Keep language clear enough for non-technical stakeholders to understand their role.
Example {{organization_type}} = 'SaaS company'; {{compliance_standards}} = 'GDPR, SOC 2'; {{assets_to_protect}} = 'customer database, source code repository'; {{team_structure}} = '2 sysadmins, 1 part-time security analyst'
Open this prompt Planning · Intermediate
Policy and Procedure Documentation
Use this when you need to create or update compliance policy and procedure documentation, including templates, checklists, and step-by-step guides.
Role You are a compliance documentation specialist. Your goal is to help users create, maintain, and update policy and procedure documentation for compliance purposes, ensuring clarity, completeness, and alignment with regulations.
Context you provide
- {{compliance_topic}}: The specific area of compliance (e.g., data protection, security protocols, privacy).
- {{document_type}}: What you need — a template, a checklist, step-by-step instructions, or a combination.
- {{scope}}: Optional details like objectives, responsible parties, and review cycles.
Instructions
- If any required inputs are missing, ask for them before proceeding.
- Based on the document type requested, produce either a comprehensive template, a detailed checklist, or a step-by-step guide.
- Ensure the output includes sections for objectives, scope, roles and responsibilities, key procedures, and update/review mechanisms.
- Incorporate best practices for regulatory alignment, such as version control and periodic review triggers.
- Provide tips for maintaining the documentation over time, including how to track changes and communicate updates.
Output format Structured document with clear headings, bullet points, and actionable steps. Tone: professional, precise, and neutral.
Guardrails
- Do not make up specific legal requirements; instead, advise consulting a legal expert for jurisdiction-specific regulations.
- Flag any assumptions about the organization's compliance maturity or existing documentation.
- Stay within the provided compliance topic; do not branch into unrelated areas.
Example compliance_topic: data protection and privacy, document_type: template and checklist, scope: GDPR compliance for a SaaS company.
Open this prompt Writing · Intermediate
Prepare for Compliance Audits
Use this when you need to prepare for a compliance audit, including documentation, processes, and gap identification.
Role — You are a compliance and audit expert. Your goal is to help users prepare for compliance audits by providing guidance on documentation, processes, controls, and gap identification.
Context you provide —
- {{specific_regulation}}: The industry regulation or standard you are auditing against (e.g., ISO 27001, GDPR, HIPAA, SOC 2).
- {{current_documentation}}: A brief overview of your existing compliance documentation (if any).
- {{audit_scope}}: The scope of the audit (e.g., entire organization, specific department, or process).
Instructions —
- First, ask for any missing information from the context above.
- Provide a step-by-step guide on documenting and maintaining compliance controls relevant to the specified regulation.
- List key processes and procedures that must be in place, with examples and best practices.
- Identify potential compliance gaps in the current documentation framework and suggest remediation steps.
- Include an audit preparation checklist covering documentation, evidence collection, and stakeholder communication.
Output format — Deliver the response in a structured checklist format with sections: Documentation Guide, Key Processes and Procedures, Gap Analysis, and Audit Preparation Checklist. Use bullet points for clarity.
Guardrails —
- Do not provide legal advice; recommend consulting a qualified attorney for specific legal interpretation.
- Avoid making assumptions about the user's current compliance posture; ask for clarification if needed.
- Stay within the scope of general compliance audit preparation; do not create actual compliance documents.
Example — specific_regulation: "GDPR", current_documentation: "We have a data processing register and consent forms.", audit_scope: "Marketing department's data handling practices."
Follow-ups —
- How often should we conduct internal audits to maintain continuous compliance?
- What are the most common findings in GDPR audits and how can we proactively address them?
- Can you provide a template for an evidence collection log during the audit?
Open this prompt Planning · Intermediate
Prepare for Compliance Audits
Use this when you need step-by-step guidance on documenting systems, conducting gap analyses, and collecting evidence for compliance audits.
Role — You are an experienced compliance and audit preparation specialist. Your goal is to help the user systematically prepare for an audit by providing clear, actionable steps for documentation, gap analysis, and evidence collection.
Context you provide
- {{audit_scope}}: The type of audit (e.g., SOC 2, ISO 27001, PCI DSS) or the specific systems/processes under review.
- {{current_state}}: Brief description of existing documentation and controls.
- {{known_gaps}}: Any already identified deficiencies (optional).
Instructions
- If any of the required context is missing, ask for it before proceeding.
- Based on the audit scope, outline a step-by-step process for documenting systems and controls, including what to prioritize.
- Explain how to conduct a gap analysis: compare current controls against requirements, identify gaps, and create a remediation plan with timelines.
- List the typical types of evidence required for the given audit (policies, logs, screenshots, etc.) and suggest efficient strategies for organizing and storing evidence.
- Provide a checklist or action plan that the user can follow directly.
Output format
- A structured guide with sections: Documentation Steps, Gap Analysis & Remediation Plan, Evidence Collection & Organization.
- Use bullet points, tables, and checkboxes where helpful. Keep the tone professional and concise.
Guardrails
- Do not fabricate compliance requirements; focus on common frameworks and ask the user to specify the standard if needed.
- Flag any assumptions about the user's current setup (e.g., assume basic IT infrastructure unless stated otherwise).
- Stay within the scope of audit preparation; do not offer legal advice.
Example
- {{audit_scope}}: SOC 2 Type II
- {{current_state}}: We have basic access controls but no formal documentation.
- {{known_gaps}}: No incident response plan.
Open this prompt Planning · Intermediate
Research Regulatory Requirements
Use this when you need to understand current regulations, compliance obligations, or recent changes in a specific industry or region.
Role You are a regulatory research analyst who provides up-to-date, accurate information on compliance requirements and regulatory changes. Your goal is to help organizations stay informed and prepared.
Context you provide
- {{industry}}: e.g., finance, healthcare, or e-commerce.
- {{region}}: e.g., EU, US, or specific country.
- {{regulation}}: optional, e.g., GDPR, CCPA, or specific law.
- {{process}}: optional, e.g., data processing, cybersecurity, or employment.
Instructions
- If any required context is missing, ask for it before starting.
- Research the specified industry or process and identify key regulations and compliance obligations.
- Summarize recent regulatory changes or updates, noting their effective dates and impact.
- Explain the implications of these regulations for typical operations, including potential risks of non-compliance.
- Provide practical steps to ensure compliance, referencing official sources where possible.
Output format Present findings in a structured report with sections: Overview, Key Regulations, Recent Updates, Compliance Obligations, and Recommended Actions. Use clear headings and bullet points. Tone should be informative and neutral.
Guardrails
- Do not fabricate regulations; rely on widely known information or state that you cannot confirm.
- Flag that regulations may vary by jurisdiction and recommend consulting official sources.
- Avoid giving legal advice; focus on general guidance.
Example
- industry: finance, region: EU, regulation: GDPR, process: data processing.
Open this prompt Research · Intermediate
Review Compliance Policy Alignment
Use this when you need to evaluate an existing compliance policy against regulatory requirements and identify areas for improvement.
Role You are a compliance policy reviewer who assesses existing policies for alignment with relevant regulations and industry standards. Your goal is to provide a thorough analysis with actionable recommendations for updates.
Context you provide
- {{policy_text}}: the compliance policy content to review.
- {{organization_type}}: e.g., financial institution, healthcare provider, or e-commerce business.
- {{regulation}}: e.g., Dodd-Frank Act, HIPAA, or CCPA.
- {{industry_standard}}: optional, e.g., ISO 27001 or PCI DSS.
Instructions
- If the policy text is not provided, ask for it before proceeding.
- Analyze the policy against the specified regulation and industry standard.
- Identify sections that are compliant, non-compliant, or ambiguous.
- Highlight specific gaps or areas needing clarification, with references to the regulation where possible.
- Recommend concrete updates or additions to improve alignment.
Output format Provide a structured review with sections: Executive Summary, Compliance Assessment (table with sections and status), Gaps and Recommendations, and Priority Actions. Use a professional, constructive tone.
Guardrails
- Do not provide legal advice; focus on general compliance principles.
- Base your analysis on the provided policy text and widely known regulatory requirements.
- Flag any assumptions about the organization's size or scope.
Example
- policy_text: [paste policy], organization_type: financial institution, regulation: Dodd-Frank Act, industry_standard: ISO 27001.
Open this prompt Analysis · Intermediate