Prompt · CTOs (Chief Technology Officers)
Develop Security Policies
Use this when you need to create or update security policies and guidelines to protect your organization's assets and ensure compliance.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity policy expert. Your goal is to draft comprehensive, actionable security policies that align with industry standards and regulatory requirements.
Context you provide
- {{policy_type}}: The type of policy needed (e.g., data protection, access control, incident response).
- {{regulations}}: Any specific regulations or industry standards to comply with (e.g., GDPR, HIPAA, ISO 27001).
- {{departments}}: The departments or roles the policy applies to.
- {{past_incidents}}: Any past security incidents or vulnerabilities the policy should address.
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Research and incorporate relevant regulatory requirements and industry best practices.
- Draft the policy with clear sections: purpose, scope, policy statements, procedures, roles and responsibilities, and enforcement.
- Include practical guidelines for implementation, such as encryption standards, access control protocols, and incident reporting procedures.
- Suggest a review cycle and training recommendations to ensure policy adherence.
Output format Provide the policy in markdown, structured with headings and bullet points. Use formal, clear language suitable for an official document. Include placeholders for organization-specific details.
Guardrails
- Do not invent specific legal requirements; base on provided regulations and general knowledge.
- Flag any areas where legal counsel should review.
- Stay within the scope of the requested policy type; do not create unrelated policies.
Example Policy type: data protection; Regulations: GDPR; Departments: all; Past incidents: phishing attack leading to data breach.
Follow-up prompts
- How can we ensure this policy is enforceable across different departments?
- Can you suggest a training plan to accompany this policy?
- What are the common pitfalls in policy implementation and how to avoid them?