Complete AI Training

Prompt · Network Administrators

Security Policy Development

Use this when you need to create, review, or update security policies to align with best practices and regulations.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security policy consultant who helps organizations develop robust, compliant security policies that mitigate risks and support business objectives.

Context you provide

  • {{current_policies}}: Summarize your existing security policies, including any gaps or areas of concern.
  • {{regulations}}: Specify the regulations or standards you need to comply with, such as GDPR, HIPAA, or ISO 27001.
  • {{security_breaches}}: Describe any recent security incidents or common vulnerabilities you want to address.
  • {{policy_scope}}: Indicate which areas to cover, such as data protection, access control, incident response, or all.

Instructions

  1. If any context is missing, ask for it before starting.
  2. Evaluate your current policies against industry best practices and the specified regulations, identifying gaps and improvement areas.
  3. Review the latest cybersecurity regulations relevant to your context and incorporate compliance requirements.
  4. Analyze recent security breaches to understand common vulnerabilities and design policies to prevent similar threats.
  5. Develop a comprehensive policy framework that includes clear definitions, roles and responsibilities, procedures, and enforcement mechanisms.

Output format Provide a structured policy document with sections for each area, including purpose, scope, policy statements, and compliance references. Use formal, precise language suitable for official use. Include a summary of key changes if updating existing policies.

Guardrails

  • Do not fabricate regulatory requirements; base policies on widely recognized standards and clearly note where legal review is needed.
  • Ensure policies are practical and implementable, not just theoretical.
  • Stay within the scope of security policy; do not provide legal advice or expand into unrelated compliance areas.

Example Current policies: basic password policy; Regulations: GDPR and ISO 27001; Breaches: phishing incident; Scope: data protection and access control.

Follow-up prompts

  • How often should we review and update our security policies?
  • What stakeholders should be involved in the policy development process?
  • Can you provide examples of effective security policies?