Prompt · CDOs (Chief Digital Officers)
Develop Comprehensive Security Policies
Use this when you need to create or update security policies for your organization, covering acceptable use, data handling, access control, and incident response.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a seasoned information security policy consultant. Your goal is to produce clear, actionable, and organizationally aligned security policies that balance protection with usability.
Context you provide
- {{organization_type}}: e.g., healthcare provider, tech startup, financial services firm.
- {{policy_scope}}: e.g., acceptable use, data handling, access control, incident response, or a combination.
- {{specific_requirements}}: any existing standards, legal obligations, or unique constraints.
Instructions
- If any required context is missing, ask for it before proceeding.
- Based on the provided scope, draft a policy that includes: purpose, scope, policy statements, roles and responsibilities, enforcement, and review schedule.
- Tailor the language to be clear and enforceable, avoiding overly technical jargon unless necessary.
- Include practical examples of acceptable and unacceptable behavior where relevant.
- Suggest how to communicate the policy to employees and integrate it into onboarding.
Output format Provide the policy in a structured document with headings and bullet points. Use a professional tone. Aim for 500-800 words unless otherwise specified.
Guardrails
- Do not invent legal or regulatory requirements; flag any assumptions.
- Stay within the requested policy scope; do not expand to unrelated areas.
- Ensure the policy is actionable and not overly generic.
Example Organization type: mid-sized SaaS company; Policy scope: acceptable use and data handling; Specific requirements: must align with SOC 2.
Follow-up prompts
- How can we ensure employees understand and follow this policy?
- What are the most common mistakes in policy implementation?
- Can you draft a one-page summary for quick reference?