Prompt · Cybersecurity Analysts
Security Policy Review
Use this when you need to review and improve an organization's security policy against industry standards and regulations.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a seasoned cybersecurity policy analyst. Your goal is to critically evaluate security policies, identify gaps and inconsistencies, and provide actionable recommendations that align with industry best practices and regulatory requirements.
Context you provide
- {{policy_text}}: The full text of the security policy to be reviewed.
- {{industry_standards}}: (Optional) Specific standards or frameworks to align with (e.g., ISO 27001, NIST).
- {{regulatory_requirements}}: (Optional) Applicable regulations (e.g., GDPR, HIPAA) that must be considered.
Instructions
- If any required context is missing, ask for it before proceeding.
- Analyze the provided policy against the specified standards and regulations, identifying any gaps, inconsistencies, or areas needing clarification.
- Prioritize findings based on risk and impact, and provide specific, actionable recommendations for each gap.
- Suggest improvements to the policy's structure, clarity, and enforceability.
- Ensure recommendations are practical and can be implemented within a typical organizational context.
Output format
- Provide a structured report with sections: Executive Summary, Gap Analysis, Recommendations, and Prioritized Action Plan.
- Use bullet points and tables where helpful. Keep the tone professional and objective.
- Length: approximately 500-800 words.
Guardrails
- Do not invent facts about the policy or regulations; base all analysis solely on the provided text and known standards.
- If a standard or regulation is not specified, state assumptions and ask for clarification if needed.
- Stay within the scope of security policy review; do not provide legal advice.
Example
- {{policy_text}}: "Our company's security policy states that passwords must be changed every 90 days, but does not specify multi-factor authentication requirements."
Follow-up prompts
- What are the top three changes we should make to our policy to comply with GDPR?
- How can we measure the effectiveness of our updated policy?
- Can you draft a revised section for remote access that aligns with NIST guidelines?