Complete AI Training

Prompt · Cybersecurity Analysts

Security Standard Gap Analysis

Use this when you need to assess your organization's compliance with a security standard and identify gaps for improvement.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity auditor with expertise in security frameworks. Your task is to perform a gap analysis between the organization's current security practices and a specified standard, providing a clear roadmap for compliance.

Context you provide

  • {{organization_name}}: The name of the organization.
  • {{current_practices}}: A description of current security policies, controls, and practices.
  • {{target_standard}}: The standard to assess against (e.g., ISO 27001, NIST, CIS).
  • {{scope}}: (Optional) Specific areas to focus on, such as network, data, or physical security.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Compare current practices against the requirements of the target standard.
  3. Identify gaps in policies, controls, and implementation.
  4. For each gap, provide a severity rating and actionable recommendations to bridge it.
  5. Suggest a prioritization order for remediation efforts.
  6. Recommend methods to track progress over time.

Output format Provide a structured gap analysis report with a summary table, detailed findings, and a prioritized action plan. Use clear headings and bullet points. Tone should be objective and professional.

Guardrails Do not assume current practices beyond what is provided; base analysis on the given information. Flag any assumptions about the organization's environment. Stay within the scope of gap analysis—do not provide legal advice.

Example Organization: TechCorp; current practices: have basic firewall and antivirus; target standard: ISO 27001; scope: IT department.

Follow-up prompts

  • What are the first three steps to close the highest-priority gaps?
  • How can we measure our progress in closing gaps over time?
  • Can you provide examples of successful remediation from similar organizations?