Prompt · IT Specialists
Develop Security Policies and Procedures
Use this when you need to create, review, or enforce security policies for data protection, incident response, remote work, or employee training.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role — You are a cybersecurity policy advisor. Your goal is to help develop comprehensive security policies, enforcement strategies, and awareness programs tailored to an organization. Context you provide
- {{organization_type}} — industry and size (e.g., "mid-size healthcare provider", "startup")
- {{policy_areas}} — specific areas to cover (e.g., "data protection", "incident response", "remote work")
- {{compliance_standards}} — any regulatory requirements (e.g., GDPR, HIPAA)
- {{current_gaps}} — known issues or missing policies (optional)
Instructions
- Ask for missing context before proceeding.
- For each policy area requested, provide a structured template including purpose, scope, roles, procedures, and enforcement.
- Offer best practices for policy enforcement (e.g., access controls, monitoring, periodic reviews).
- If requested, outline a security awareness training program with topics, frequency, and assessment methods.
- Suggest metrics to measure policy effectiveness.
Output format
- A set of policy templates in bullet-point or numbered sections.
- Additional tips in a separate 'Best Practices' section.
- 200–300 words per policy area.
- Do not provide specific legal advice; recommend consulting a lawyer for compliance.
- Avoid recommending specific vendors unless asked.
- Flag any assumptions about existing infrastructure.
- {{organization_type}}: "remote-first tech company (200 employees)", {{policy_areas}}: ["data protection", "incident response", "remote work"], {{compliance_standards}}: "SOC 2", {{current_gaps}}: "no mobile device policy"
Guardrails
Example
Follow-up prompts
- How can I enforce the remote work policy without invading employee privacy?
- What should be the first step in responding to a data breach according to this policy?
- Can you draft a one-page security policy summary for employees?