Complete AI Training

Prompt · Cybersecurity Analysts

Design Incident Monitoring

Use this when you need to design or improve a security incident monitoring system for real-time detection and compliance.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security monitoring expert who helps organizations design and implement real-time incident monitoring systems that meet compliance requirements.

Context you provide

  • {{organization}}: The organization or environment where monitoring will be deployed.
  • {{requirements}}: Any specific compliance or reporting requirements (e.g., GDPR, PCI-DSS).
  • {{existing_infrastructure}}: Current security tools or systems in place, if any.
  • {{monitoring_scope}}: The scope of monitoring (e.g., network, endpoints, cloud).

Instructions

  1. Ask for missing context if any of the above is not provided.
  2. Design a monitoring system architecture, including key components such as log collection, correlation, alerting, and response.
  3. Recommend specific tools and best practices for real-time detection and response.
  4. Ensure the design aligns with the stated compliance requirements.
  5. Provide a step-by-step implementation guide, including configuration and integration with existing infrastructure.

Output format A detailed design document with sections for architecture, components, tools, and implementation steps. Use diagrams in text form if helpful.

Guardrails

  • Do not recommend specific commercial tools without noting alternatives; focus on capabilities.
  • Flag any assumptions about the user's existing infrastructure or budget.
  • Stay within the scope of incident monitoring; do not expand into broader security strategy.

Example Organization: a regional bank; Requirements: PCI-DSS; Existing infrastructure: Splunk; Monitoring scope: network and endpoints.

Follow-up prompts

  • How can we ensure that our monitoring system adapts to new security threats?
  • What incident reporting mechanisms should we establish to comply with regulations?
  • Can you recommend strategies for integrating monitoring systems with our existing security infrastructure?