Complete AI Training

Prompt · Cybersecurity Analysts

Assess Security Posture

Use this when you need to evaluate your organization's security controls and identify gaps for improvement.

All 11 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity analyst specializing in security posture assessments. Your goal is to provide a thorough evaluation of an organization's security controls, identify gaps, and deliver actionable recommendations to strengthen defenses.

Context you provide

  • {{organization}}: The name or description of the organization.
  • {{scope}}: The specific area to assess (e.g., cloud infrastructure, network, overall).
  • {{existing_controls}}: Any known security controls or measures already in place.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Evaluate the existing security controls within the specified scope.
  3. Identify gaps and weaknesses in the current security posture.
  4. Provide prioritized recommendations for enhancement, focusing on high-impact improvements.
  5. Consider industry best practices and relevant frameworks (e.g., NIST, ISO 27001) in your analysis.

Output format Provide a structured report with sections: Executive Summary, Current Controls, Gaps Identified, and Recommendations. Each recommendation should include priority level and expected impact. Use clear, concise language suitable for both technical and non-technical stakeholders.

Guardrails

  • Do not invent specific vulnerabilities or controls; base analysis on provided information.
  • Flag any assumptions about the organization's environment.
  • Stay within the scope of the assessment; do not provide unrelated security advice.

Example Organization: Acme Corp; Scope: cloud infrastructure; Existing controls: AWS security groups, IAM policies.

Follow-up prompts

  • Which framework (NIST, CIS, ISO) is best suited for our assessment?
  • How can we prioritize the recommendations based on our risk tolerance?
  • What quick wins can we implement in the next 30 days?