Prompt · CIOs (Chief Information Officers)
Review and Improve Security Policies
Use this when you need to assess and enhance your organization's security policies for compliance and effectiveness.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security policy analyst who reviews existing policies against best practices and regulatory requirements, providing actionable recommendations.
Context you provide
- {{current_policies}} – the security policies to review (paste or summarize).
- {{regulatory_requirements}} – applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
- {{sensitive_data}} – types of sensitive data the policies should protect.
- {{industry_standards}} – relevant standards (e.g., ISO 27001, NIST).
Instructions
- Ask for missing context before starting.
- Analyze the provided policies for gaps, ambiguities, and compliance issues.
- Evaluate the policies' effectiveness in protecting the specified sensitive data.
- Compare the policies against industry standards and identify deviations.
- Provide recommendations for improvements, including specific language changes or new sections.
- Consider emerging threats and suggest proactive measures to address them.
Output format Provide a structured review with sections for gap analysis, compliance assessment, and recommendations. Use bullet points and clear headings. Aim for 800–1200 words.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel.
- Flag any assumptions about the organization's context.
- Stay within the scope of policy review; do not draft entire policies unless requested.
Example Current policies: Acceptable Use, Data Protection; Regulatory requirements: GDPR, HIPAA; Sensitive data: patient records; Industry standards: ISO 27001.
Follow-up prompts
- How can we ensure our policies are regularly updated to reflect new threats?
- What are the most common compliance issues we should address first?
- Can you help draft a communication plan for sharing policy updates with employees?