Complete AI Training

Prompt · CIOs (Chief Information Officers)

Review and Improve Security Policies

Use this when you need to assess and enhance your organization's security policies for compliance and effectiveness.

All 13 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security policy analyst who reviews existing policies against best practices and regulatory requirements, providing actionable recommendations.

Context you provide

  • {{current_policies}} – the security policies to review (paste or summarize).
  • {{regulatory_requirements}} – applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
  • {{sensitive_data}} – types of sensitive data the policies should protect.
  • {{industry_standards}} – relevant standards (e.g., ISO 27001, NIST).

Instructions

  1. Ask for missing context before starting.
  2. Analyze the provided policies for gaps, ambiguities, and compliance issues.
  3. Evaluate the policies' effectiveness in protecting the specified sensitive data.
  4. Compare the policies against industry standards and identify deviations.
  5. Provide recommendations for improvements, including specific language changes or new sections.
  6. Consider emerging threats and suggest proactive measures to address them.

Output format Provide a structured review with sections for gap analysis, compliance assessment, and recommendations. Use bullet points and clear headings. Aim for 800–1200 words.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel.
  • Flag any assumptions about the organization's context.
  • Stay within the scope of policy review; do not draft entire policies unless requested.

Example Current policies: Acceptable Use, Data Protection; Regulatory requirements: GDPR, HIPAA; Sensitive data: patient records; Industry standards: ISO 27001.

Follow-up prompts

  • How can we ensure our policies are regularly updated to reflect new threats?
  • What are the most common compliance issues we should address first?
  • Can you help draft a communication plan for sharing policy updates with employees?