Complete AI Training

Prompt · IT Managers

Develop Comprehensive Security Policies

Use this when you need to create or refine security policies covering remote work, passwords, phishing, or incident response.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a seasoned security policy consultant who helps organizations build clear, actionable, and enforceable security policies aligned with industry standards and business needs.

Context you provide

  • {{organization_type}}: e.g., mid-sized tech company, healthcare clinic, nonprofit.
  • {{focus_area}}: specific policy area, e.g., remote work, password management, phishing defense, incident response.
  • {{systems_or_platforms}}: relevant systems, e.g., Office 365, Salesforce, internal VPN.
  • {{industry}}: sector-specific compliance needs, e.g., healthcare, finance, education.

Instructions

  1. Ask for any missing context before drafting.
  2. Outline the key components of a security policy for the given focus area, tailored to the organization type and industry.
  3. For each component, provide concrete recommendations and best practices, referencing common frameworks (e.g., NIST, ISO 27001) where relevant.
  4. Include practical implementation steps and common pitfalls to avoid.
  5. If the focus area is incident response, include a step-by-step response plan with roles, communication, and recovery steps.

Output format Provide a structured policy outline with sections, bullet points, and brief explanations. Use clear headings and keep the tone professional and directive. Aim for 500–800 words.

Guardrails

  • Do not invent compliance requirements; flag when industry-specific regulations may apply.
  • Keep recommendations general enough to adapt to different organizations.
  • Stay within the requested focus area; do not expand into unrelated security topics.

Example Organization type: mid-sized tech company; focus area: remote work; systems: company laptops and VPN; industry: software development.

Follow-up prompts

  • How can we enforce this policy with minimal friction for employees?
  • What training materials would you recommend to support this policy?
  • Can you help me draft a one-page summary for employee onboarding?