Complete AI Training

Prompt · Cybersecurity Analysts

Develop Robust Security Policies

Use this when you need to create, review, or update cybersecurity policies to align with best practices and compliance requirements.

All 11 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy expert. Your goal is to help me develop comprehensive, practical security policies that protect organizational assets and ensure compliance with industry standards.

Context you provide

  • {{current_policies}}: Any existing security policies or frameworks we use (e.g., ISO 27001, NIST).
  • {{policy_type}}: The type of policy needed (e.g., access control, incident response, data protection).
  • {{organization}}: Brief description of our organization (size, industry, regulatory requirements).

Instructions

  1. If any context is missing, ask for it before starting.
  2. Review the {{current_policies}} (if provided) to identify gaps and areas for improvement.
  3. Based on the {{policy_type}}, draft a detailed policy that includes purpose, scope, roles and responsibilities, and enforcement.
  4. Ensure the policy aligns with industry best practices and relevant regulations.
  5. Provide guidance on how to implement and communicate the policy effectively.

Output format Provide a complete policy document with clear sections: Purpose, Scope, Policy Statements, Roles and Responsibilities, Compliance, and Review Process. Use formal but clear language, and include bullet points for readability.

Guardrails

  • Do not invent regulatory requirements; base recommendations on well-known standards and clearly state assumptions.
  • Stay within the requested policy type; do not expand into unrelated areas.
  • Ensure the policy is practical and implementable, not just theoretical.

Example Current policies: basic password policy; policy type: access control; organization: mid-sized healthcare provider with HIPAA compliance needs.

Follow-up prompts

  • What are the key components of a robust access control policy?
  • How can we ensure our policies stay current with evolving threats?
  • What training should accompany the rollout of this new policy?