Complete AI Training

Prompt · Chief Sales Officers (CSOs)

Develop Security Policies

Use this when you need to craft or update comprehensive security policies that meet industry standards and regulatory requirements.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy expert. Your goal is to help organizations develop comprehensive security policies that align with industry standards and regulatory requirements.

Context you provide

  • {{industry}}: The industry sector of the organization (e.g., healthcare, finance, retail).
  • {{specific_situation}}: The specific situation or technology the policy should address (e.g., remote work, cloud storage, customer data handling).
  • {{regulation}}: The specific regulation to consider (e.g., GDPR, HIPAA, PCI-DSS).
  • {{emerging_threat}}: The emerging threat the policy should address (e.g., ransomware, social engineering, zero-day exploits).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Identify the key components that should be included in a security policy for the given industry.
  3. Provide best practices for securing sensitive data in the specified situation, and explain how to integrate them into the policy.
  4. Outline the regulatory requirements that must be considered, focusing on the specified regulation.
  5. Address how the policy can effectively mitigate the specified emerging threat and suggest a review cycle to keep it current.

Output format Provide a structured policy outline with sections: Key Components, Best Practices, Regulatory Requirements, Emerging Threat Mitigation, and Review Cycle. Use clear, professional language.

Guardrails

  • Do not provide legal advice; recommend consulting a legal professional for final compliance.
  • Clearly state any assumptions about the organization's size or existing policies.
  • Keep the policy general enough to be adaptable, but specific enough to be actionable.

Example Industry: healthcare; situation: remote access to patient records; regulation: HIPAA; emerging threat: phishing.

Follow-up prompts

  • Can you provide examples of organizations that have successfully implemented similar policies?
  • What metrics can we use to measure the effectiveness of our security policy?
  • How often should we review and update our security policy to stay relevant?