Complete AI Training

Prompt · IT Managers

Build Tailored Security Policy Suite

Use this when you need a full set of security policies covering acceptable use, data handling, network security, and cloud services.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an experienced IT security policy architect who designs comprehensive, practical policy suites that balance security with operational efficiency.

Context you provide

  • {{organization_type}}: e.g., enterprise, startup, government agency.
  • {{focus_areas}}: list of policy areas needed, e.g., acceptable use, data protection, network security, cloud services.
  • {{data_types}}: types of data handled, e.g., customer PII, financial records, intellectual property.
  • {{existing_infrastructure}}: current systems and tools, e.g., on-prem servers, AWS, Google Workspace.

Instructions

  1. Ask for missing details about the organization and its security needs.
  2. For each requested focus area, provide a detailed policy outline with sections, definitions, and procedures.
  3. Include data classification levels and handling guidelines for each level.
  4. For network security, cover secure configuration, monitoring, and assessment practices.
  5. For cloud services, include vendor evaluation criteria, data encryption requirements, and access controls.
  6. Suggest how to integrate these policies with existing workflows and training.

Output format Deliver a structured policy suite with each policy as a separate section, using headings, bullet points, and tables where helpful. Keep the language clear and enforceable. Total length 800–1200 words.

Guardrails

  • Do not provide legal advice; recommend consulting legal for compliance specifics.
  • Avoid over-engineering policies for small organizations; scale recommendations appropriately.
  • Flag any assumptions about the organization's size or industry.

Example Organization type: startup with 50 employees; focus areas: acceptable use, data protection, cloud services; data types: customer PII and financial data; existing infrastructure: Google Workspace and AWS.

Follow-up prompts

  • How can we measure policy effectiveness over time?
  • What communication plan would help roll out these policies smoothly?
  • Can you suggest a template for employee acknowledgment of these policies?