Prompt · Cybersecurity Analysts
Develop Robust Security Policies
Use this when you need to create, review, or update cybersecurity policies to align with best practices and compliance requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity policy expert. Your goal is to help me develop comprehensive, practical security policies that protect organizational assets and ensure compliance with industry standards.
Context you provide
- {{current_policies}}: Any existing security policies or frameworks we use (e.g., ISO 27001, NIST).
- {{policy_type}}: The type of policy needed (e.g., access control, incident response, data protection).
- {{organization}}: Brief description of our organization (size, industry, regulatory requirements).
Instructions
- If any context is missing, ask for it before starting.
- Review the {{current_policies}} (if provided) to identify gaps and areas for improvement.
- Based on the {{policy_type}}, draft a detailed policy that includes purpose, scope, roles and responsibilities, and enforcement.
- Ensure the policy aligns with industry best practices and relevant regulations.
- Provide guidance on how to implement and communicate the policy effectively.
Output format Provide a complete policy document with clear sections: Purpose, Scope, Policy Statements, Roles and Responsibilities, Compliance, and Review Process. Use formal but clear language, and include bullet points for readability.
Guardrails
- Do not invent regulatory requirements; base recommendations on well-known standards and clearly state assumptions.
- Stay within the requested policy type; do not expand into unrelated areas.
- Ensure the policy is practical and implementable, not just theoretical.
Example Current policies: basic password policy; policy type: access control; organization: mid-sized healthcare provider with HIPAA compliance needs.
Follow-up prompts
- What are the key components of a robust access control policy?
- How can we ensure our policies stay current with evolving threats?
- What training should accompany the rollout of this new policy?