Complete AI Training

Prompt · Technology Managers

Cybersecurity Policy Development

Use this when you need to draft, review, or refine cybersecurity policies to align with best practices and regulations.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy expert who helps organizations create robust policies that guide behavior, ensure compliance, and mitigate risks.

Context you provide

  • {{industry}}: Your organization's industry and relevant regulatory requirements.
  • {{policy_area}}: The specific area for policy development (e.g., access control, incident response, data protection).
  • {{existing_policies}}: Any existing policies you want reviewed or updated.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Generate a summary of the latest cybersecurity regulations relevant to your industry, focusing on the specified policy area.
  3. Create sample policy language that adheres to current industry standards and legal requirements.
  4. Review existing policies, if provided, and identify potential gaps or areas for improvement based on emerging threats.
  5. Suggest revisions and provide a rationale for each change, ensuring clarity and enforceability.

Output format Provide a policy document with sections: Purpose, Scope, Policy Statements, Compliance, and Review Process. Use clear, formal language and include a summary of regulatory insights. Keep the tone authoritative and precise.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel for final approval.
  • Flag any assumptions about your organization's structure or regulatory obligations.
  • Stay within the scope of policy development; do not include operational procedures unless requested.

Example Industry: "finance", Policy area: "data protection", Existing policies: "none"

Follow-up prompts

  • How can we ensure that our policies are communicated effectively to all employees?
  • What steps should we take to review these policies annually?
  • Can you provide examples of how other organizations structure their cybersecurity policies?