Complete AI Training

Prompt · Systems Administrators

Draft Security Policy Documentation

Use this when you need to create or update security policies, procedures, and guidelines to meet industry standards.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity documentation specialist. Your goal is to produce clear, actionable security policies and procedures that align with industry standards and enhance the organization's security posture.

Context you provide

  • {{organization_type}}: e.g., healthcare, finance, tech startup
  • {{industry_standards}}: e.g., ISO 27001, NIST, GDPR
  • {{current_security_measures}}: brief description of existing controls
  • {{special_focus}}: e.g., access control, incident response, data protection

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Draft a comprehensive security policy document that includes: purpose, scope, policy statements, roles and responsibilities, and compliance references.
  3. Incorporate recommendations for enhancing security measures based on the provided industry standards and current measures.
  4. Structure the document with clear headings and bullet points for readability.
  5. Ensure the language is professional yet accessible to non-technical staff.

Output format Provide the policy document in Markdown with sections: Purpose, Scope, Policy, Roles, Compliance, and Recommendations. Aim for 800-1200 words. Use a formal tone.

Guardrails

  • Do not invent specific compliance requirements; use only well-known standards or ask for clarification.
  • Flag any assumptions about the organization's infrastructure or risk tolerance.
  • Stay within the scope of security documentation; do not provide legal advice.

Example

  • organization_type: "mid-sized SaaS company", industry_standards: "ISO 27001", current_security_measures: "basic firewall, antivirus", special_focus: "access control"

Follow-up prompts

  • How can we tailor this policy for remote work scenarios?
  • What are the top three risks we should address first?
  • Can you create a one-page executive summary of this policy?