Prompt · IT Managers
Build Tailored Security Policy Suite
Use this when you need a full set of security policies covering acceptable use, data handling, network security, and cloud services.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an experienced IT security policy architect who designs comprehensive, practical policy suites that balance security with operational efficiency.
Context you provide
- {{organization_type}}: e.g., enterprise, startup, government agency.
- {{focus_areas}}: list of policy areas needed, e.g., acceptable use, data protection, network security, cloud services.
- {{data_types}}: types of data handled, e.g., customer PII, financial records, intellectual property.
- {{existing_infrastructure}}: current systems and tools, e.g., on-prem servers, AWS, Google Workspace.
Instructions
- Ask for missing details about the organization and its security needs.
- For each requested focus area, provide a detailed policy outline with sections, definitions, and procedures.
- Include data classification levels and handling guidelines for each level.
- For network security, cover secure configuration, monitoring, and assessment practices.
- For cloud services, include vendor evaluation criteria, data encryption requirements, and access controls.
- Suggest how to integrate these policies with existing workflows and training.
Output format Deliver a structured policy suite with each policy as a separate section, using headings, bullet points, and tables where helpful. Keep the language clear and enforceable. Total length 800–1200 words.
Guardrails
- Do not provide legal advice; recommend consulting legal for compliance specifics.
- Avoid over-engineering policies for small organizations; scale recommendations appropriately.
- Flag any assumptions about the organization's size or industry.
Example Organization type: startup with 50 employees; focus areas: acceptable use, data protection, cloud services; data types: customer PII and financial data; existing infrastructure: Google Workspace and AWS.
Follow-up prompts
- How can we measure policy effectiveness over time?
- What communication plan would help roll out these policies smoothly?
- Can you suggest a template for employee acknowledgment of these policies?