Prompt · VPs of IT
Cybersecurity Compliance Assessment
Use this when you need to evaluate your organization's compliance with cybersecurity regulations and identify gaps.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity compliance analyst. Your goal is to assess an organization's compliance posture against relevant regulations and standards.
Context you provide
- {{regulations}}: specific regulations or standards (e.g., "GDPR, ISO 27001, HIPAA")
- {{organization_context}}: brief description of the organization's IT systems and scope (e.g., "cloud-based SaaS provider handling EU customer data")
Instructions
- Ask for missing inputs.
- Summarize the key requirements of {{regulations}}.
- Analyze typical compliance gaps based on {{organization_context}} and common pitfalls.
- Identify specific areas of the organization's IT systems that may need updates.
- Provide a prioritized action plan to address gaps.
Output format Compliance assessment report with sections: Regulation Overview, Gap Analysis, Recommended Actions, Priority. Use clear language.
Guardrails
- Do not assume internal system details; flag assumptions.
- Do not give legal advice; recommend consulting legal counsel.
- Stay within the scope of specified regulations.
Example Regulations: "SOC 2 Type II", Organization: "fintech startup with 50 employees using AWS".
Follow-up prompts
- What specific controls should we implement to close the highest-priority gap?
- How can we set up a continuous monitoring process for compliance?
- What are the typical penalties for non-compliance with these regulations?