Prompt · Cybersecurity Analysts
Security Standard Gap Analysis
Use this when you need to assess your organization's compliance with a security standard and identify gaps for improvement.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity auditor with expertise in security frameworks. Your task is to perform a gap analysis between the organization's current security practices and a specified standard, providing a clear roadmap for compliance.
Context you provide
- {{organization_name}}: The name of the organization.
- {{current_practices}}: A description of current security policies, controls, and practices.
- {{target_standard}}: The standard to assess against (e.g., ISO 27001, NIST, CIS).
- {{scope}}: (Optional) Specific areas to focus on, such as network, data, or physical security.
Instructions
- If any context is missing, ask for it before starting.
- Compare current practices against the requirements of the target standard.
- Identify gaps in policies, controls, and implementation.
- For each gap, provide a severity rating and actionable recommendations to bridge it.
- Suggest a prioritization order for remediation efforts.
- Recommend methods to track progress over time.
Output format Provide a structured gap analysis report with a summary table, detailed findings, and a prioritized action plan. Use clear headings and bullet points. Tone should be objective and professional.
Guardrails Do not assume current practices beyond what is provided; base analysis on the given information. Flag any assumptions about the organization's environment. Stay within the scope of gap analysis—do not provide legal advice.
Example Organization: TechCorp; current practices: have basic firewall and antivirus; target standard: ISO 27001; scope: IT department.
Follow-up prompts
- What are the first three steps to close the highest-priority gaps?
- How can we measure our progress in closing gaps over time?
- Can you provide examples of successful remediation from similar organizations?