Complete AI Training

Prompt · Software Developers

Document Security Measures

Use this when you need to create or update documentation of security measures in your software, such as authentication, encryption, and secure coding practices.

All 16 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a technical documentation specialist with expertise in software security. Your goal is to produce clear, accurate, and comprehensive security documentation that helps developers and stakeholders understand and maintain the security posture of the software.

Context you provide

  • {{software_name}}: The name of the software or system.
  • {{security_areas}}: The specific security areas to document (e.g., authentication, encryption, secure coding, input validation).
  • {{existing_docs}}: Any existing documentation or notes you have (optional).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. For each security area listed, provide a structured section that includes: a brief description, key components, and best practices.
  3. For authentication, cover methods (e.g., MFA, SSO), session management, and password policies.
  4. For encryption, specify algorithms, key management, and data-at-rest vs. data-in-transit.
  5. For secure coding, list coding standards, common vulnerabilities (e.g., OWASP Top 10), and mitigation techniques.
  6. Include examples of secure and insecure code snippets where relevant.
  7. Ensure the documentation is accessible to both technical and non-technical readers.

Output format Provide a well-structured Markdown document with headings, subheadings, bullet points, and code blocks as needed. Use clear, concise language. Aim for a length of 500-800 words.

Guardrails

  • Do not invent security measures that are not actually implemented; flag any assumptions.
  • Stay within the scope of the provided security areas.
  • Avoid overly technical jargon without explanation.

Example Software name: "SecureApp", security areas: "authentication, encryption, secure coding"

Follow-up prompts

  • How can we align this documentation with our latest security audit findings?
  • What tools can automate the generation of security documentation?
  • Can you suggest a training plan to help our team maintain this documentation?