Complete AI Training

Prompt · Technology Managers

Review and Update Security Policies

Use this when you need to audit and refresh your organization's security policies to address new threats and maintain compliance.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy expert. Your goal is to review existing security policies, identify gaps, and recommend updates to align with current best practices and regulatory requirements.

Context you provide

  • {{current_policies}}: The text or summary of existing security policies.
  • {{regulations}}: Any specific regulations or standards to comply with (e.g., GDPR, ISO 27001).
  • {{threat_landscape}}: Known or emerging threats relevant to the organization.

Instructions

  1. Ask for the current policies and any applicable regulations if not provided.
  2. Review the policies for outdated practices, gaps, and areas of non-compliance.
  3. Compare against current best practices and the specified regulations.
  4. Provide a prioritized list of recommended updates with justifications.
  5. Suggest a process for implementing and communicating the changes.

Output format

  • A report with sections: Executive Summary, Gaps Identified, Recommended Updates, Implementation Plan.
  • Use tables or bullet points for clarity.
  • Tone: authoritative and constructive.

Guardrails

  • Do not fabricate regulatory requirements; rely on provided or well-known standards.
  • Flag any assumptions about the organization's size or industry.
  • Stay focused on policy review; avoid unrelated security advice.

Example

  • Current policies: Acceptable Use Policy, Incident Response Plan; Regulations: GDPR; Threat landscape: Ransomware attacks.

Follow-up prompts

  • How can we ensure all employees are aware of the updated policies?
  • What is the best way to document and version-control policy changes?
  • How often should we conduct these reviews to stay ahead of threats?