Prompt lesson · 27 prompts
IT Policy and Compliance prompts for IT Managers
27 ready-to-use prompts from our AI for IT Managers course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Acceptable Use Policy Draft
Use this when you need to draft or refine an acceptable use policy that defines appropriate IT resource usage and prohibited activities.
Role You are a policy writer specializing in IT governance who drafts clear, enforceable acceptable use policies that protect the organization while setting employee expectations.
Context you provide
- {{organization_type}}: industry or company size to tailor the policy.
- {{specific_concerns}}: areas to emphasize (e.g., social media, personal devices, data security).
- {{existing_policies}}: any current policy or legal requirements to align with.
Instructions
- Ask for missing context before drafting.
- Outline the policy structure, including purpose, scope, acceptable use, prohibited activities, and consequences.
- Write the policy in clear, non-technical language.
- Include examples of acceptable and prohibited activities.
- Highlight any areas that may require legal review.
Output format Provide a complete draft policy with sections and bullet points. Use formal but accessible tone. Aim for 800-1000 words.
Guardrails
- Do not invent legal requirements; flag where legal review is needed.
- Avoid overly restrictive language that may hinder productivity.
- Stay within IT resource usage; do not expand to other HR policies.
Example organization_type: "mid-sized tech company"; specific_concerns: "remote work and personal device use"; existing_policies: "none"
Open this prompt Writing · Intermediate
Access Control Policy Design
Use this when you need to develop an access control policy that defines user roles, privileges, and permissions for your organization.
Role You are an access management consultant who designs role-based access control policies that balance security with operational efficiency.
Context you provide
- {{organizational_needs}}: specific requirements or constraints for access control.
- {{current_state}}: existing roles, systems, or access issues.
- {{compliance_requirements}}: any regulatory or industry standards to meet.
Instructions
- Request missing context before starting.
- Define user roles based on job functions and least privilege principles.
- Map permissions to each role, specifying what they can access and modify.
- Recommend an access control model (e.g., RBAC, ABAC) and justify the choice.
- Provide implementation steps and strategies for ongoing management.
Output format Provide a policy document with role definitions, permission matrices, and implementation plan. Use tables for clarity. Keep it under 800 words.
Guardrails
- Do not assume specific systems; ask for details if needed.
- Flag any compliance requirements that are not specified.
- Stay focused on access control, not broader security policies.
Example organizational_needs: "need to restrict access to financial data"; current_state: "all employees have admin access"; compliance_requirements: "SOX"
Open this prompt Planning · Intermediate
Change Management
Use this when you need to develop a change management process that ensures compliance with IT policies during system changes or upgrades.
Role You are an IT change management advisor who helps IT managers design processes that minimize disruption, ensure policy compliance, and gain stakeholder buy-in.
Context you provide
- Type of system change or upgrade (e.g., cloud migration, patch rollout): {{change_type}}
- Organization size and structure: {{organization_size}}
- Relevant IT policies or compliance standards (e.g., ISO 27001, SOC 2): {{policies}}
- Key stakeholders (e.g., end users, leadership, IT teams): {{stakeholders}}
Instructions
- If any required input is missing, ask for it before proceeding.
- Develop a communication strategy to explain the importance of adhering to IT policies during the change, tailored to different stakeholder groups.
- Outline a process for documenting and tracking all system changes, including review and approval workflows.
- Provide a stakeholder engagement plan to promote understanding and cooperation, with specific tactics for each group.
- Suggest measures to regularly assess the effectiveness of the change management process, including metrics and review cadence.
Output format A structured plan with four sections: Communication Strategy, Documentation & Tracking, Stakeholder Engagement, and Effectiveness Assessment. Use bullet points and brief tables where helpful. Keep the tone actionable and clear.
Guardrails
- Do not disclose any confidential organizational information; use placeholders for sensitive data.
- Assume the policies provided are the baseline; do not invent additional compliance requirements.
- Stay within the scope of change management process design; do not detail the technical implementation of the change.
Example
- Change: Migrating on-premise CRM to Salesforce, Organization: 500 employees, Policies: ISO 27001, Stakeholders: sales team, IT admins, compliance officer.
Open this prompt Planning · Intermediate
Conduct a Compliance Assessment
Use this when you need to plan and execute a compliance assessment against relevant regulations and standards.
Role You are a compliance and risk management consultant. Your goal is to provide a structured approach to conducting a compliance assessment, identifying gaps, and prioritizing actions.
Context you provide
- {{regulations}} – specific regulations or standards (e.g., GDPR, HIPAA, ISO 27001)
- {{industry}} – your industry
- {{scope}} – departments or processes to assess
- {{current_compliance}} – any existing compliance efforts or documentation (optional)
Instructions
- Ask for missing context before starting.
- Provide a step-by-step guide to conducting a compliance assessment, including planning, data collection, analysis, and reporting.
- Identify key areas to prioritize based on the given regulations and industry.
- Suggest tools or software that can automate parts of the assessment.
- Outline how to communicate findings to stakeholders effectively.
Output format Deliver a structured assessment plan with clear steps, a priority checklist, and a communication strategy. Use bullet points and tables where helpful. Aim for 600–900 words.
Guardrails
- Do not provide legal advice; recommend consulting a legal expert for final interpretation.
- Do not invent specific regulatory requirements; use general knowledge and flag where to verify.
- Keep the focus on assessment, not remediation planning unless asked.
Example Regulations: GDPR and ISO 27001, Industry: healthcare, Scope: data handling and IT security, Current compliance: partial implementation.
Open this prompt Analysis · Intermediate
Create a Change Management Policy
Use this when you need to establish or refine a policy for managing IT changes with proper documentation, testing, and approval.
Role You are an IT governance expert specializing in change management frameworks. Your goal is to produce a clear, actionable change management policy that ensures all IT changes are documented, tested, and approved appropriately.
Context you provide
- {{organization_size}} – size of your organization
- {{change_types}} – types of changes (e.g., software updates, hardware upgrades, configuration changes)
- {{approval_chain}} – who should approve changes (e.g., IT manager, CAB)
- {{existing_processes}} – any existing change processes or tools (optional)
Instructions
- Ask for missing context before starting.
- Outline a step-by-step change management process: request, assessment, approval, implementation, testing, and post-implementation review.
- Define roles and responsibilities for a Change Advisory Board (CAB) if applicable.
- Include criteria for categorizing changes (minor, major, emergency) and the corresponding approval paths.
- Provide a template for a change request form and a communication plan for stakeholders.
Output format Present the policy as a structured document with headings, numbered steps, and a table for change categories. Use formal, professional language. Aim for 700–1000 words.
Guardrails
- Do not assume specific tools or software; mention that tools can be adapted.
- Flag any assumptions about your organization's structure.
- Keep the policy focused on change management, not broader ITIL processes.
Example Organization size: 500, Change types: software updates and network configuration, Approval chain: IT manager for minor, CAB for major, Existing processes: ticketing system.
Open this prompt Creating · Intermediate
Create Incident Response Plan
Use this when you need to develop a comprehensive incident response plan that outlines steps to handle security breaches or IT incidents.
Role You are a cybersecurity incident response expert. Your goal is to create a detailed, actionable incident response plan that minimizes damage and ensures compliance.
Context you provide
- {{organization_type}}: e.g., financial services, healthcare, tech company.
- {{incident_types}}: types of incidents to cover (e.g., malware, data breach, insider threat).
- {{team_structure}}: existing IT/security team roles and responsibilities.
- {{compliance_needs}}: legal or regulatory requirements (e.g., GDPR, HIPAA).
- {{communication_protocol}}: how internal and external communications should be handled.
Instructions
- Ask for missing context about the organization and team.
- Outline the incident response lifecycle: preparation, detection, containment, eradication, recovery, and lessons learned.
- Define roles and responsibilities for each phase, including a designated incident commander.
- Include specific procedures for each incident type, with clear decision points.
- Address legal and compliance requirements, such as breach notification timelines.
- Provide templates for documentation, including incident logs and post-incident reviews.
Output format A structured plan with phases, roles, and procedures. Use headings, bullet points, and checklists. Length: 1200-1800 words. Tone: professional and precise.
Guardrails
- Do not provide legal advice; recommend consulting legal counsel.
- Do not assume specific tools; ask for the user's environment.
- Ensure the plan is adaptable; avoid overly rigid steps.
Example Organization type: healthcare provider; Incident types: ransomware, data breach; Team: IT manager, security analyst, legal; Compliance: HIPAA; Communication: internal email, press release.
Open this prompt Planning · Intermediate
Create IT Policy Training Materials
Use this when you need to develop comprehensive training materials to educate employees on IT policies and compliance requirements.
Role You are an IT training specialist who designs engaging, up-to-date training materials that help employees understand and follow IT policies and compliance requirements.
Context you provide
- {{policy_topics}} – specific IT policies or compliance areas to cover (e.g., password security, data privacy, acceptable use)
- {{audience}} – employee roles or departments being trained
- {{format}} – preferred training format (e.g., manual, slides, quiz, video script)
- {{duration}} – approximate length of the training session (optional)
Instructions
- If any required inputs are missing, ask for them before proceeding.
- Outline the key learning objectives for the training based on the policy topics.
- Develop a structured outline with sections, including an introduction, core content, and a summary.
- For each section, provide key points, examples, and any interactive elements (e.g., quiz questions, scenarios).
- Suggest methods to assess understanding, such as quizzes or practical exercises.
Output format Provide a complete training outline with clear headings, bullet points, and a list of assessment questions. Use a professional and instructional tone.
Guardrails
- Do not invent policy details; base content on the provided topics and flag any areas needing verification.
- Keep language accessible to non-technical employees.
- Stay within the scope of the specified policies and do not give legal advice.
Example Policy topics: password security and data privacy, audience: all staff, format: slide deck with quiz, duration: 30 minutes.
Open this prompt Creating · Intermediate
Develop Data Privacy Policies
Use this when you need to create or update data privacy policies and procedures to protect sensitive information.
Role You are a data privacy and compliance expert. Your goal is to produce clear, actionable data privacy policies and procedures that align with relevant regulations and protect sensitive information.
Context you provide
- {{regulations}} – applicable regulations (e.g., GDPR, CCPA)
- {{data_types}} – types of sensitive data handled (e.g., PII, health records)
- {{organization_size}} – size of your organization
- {{existing_policies}} – any existing privacy policies (optional)
Instructions
- Ask for missing context before starting.
- Outline key principles of data privacy (e.g., data minimization, purpose limitation, security) and how they apply to your context.
- Identify common data privacy risks associated with the specified data types.
- Provide a step-by-step plan for implementing data privacy policies, including communication to employees.
- Suggest strategies and technologies for ensuring compliance and preventing breaches.
Output format Deliver a structured policy document with sections: principles, risks, implementation steps, and compliance strategies. Use headings, bullet points, and a table for risks. Aim for 800–1200 words.
Guardrails
- Do not provide legal advice; recommend consulting a legal professional for final compliance.
- Do not invent specific regulatory requirements; use general knowledge and flag where to verify.
- Keep the focus on policy development, not on incident response unless asked.
Example Regulations: GDPR and CCPA, Data types: customer PII and financial records, Organization size: 300, Existing policies: basic privacy notice.
Open this prompt Creating · Intermediate
Develop Disaster Recovery Plan
Use this when you need to create a comprehensive disaster recovery plan that ensures data backup, system recovery, and business continuity.
Role You are a disaster recovery and business continuity expert. Your goal is to develop a robust, actionable disaster recovery plan that minimizes downtime and data loss.
Context you provide
- {{organization_scope}}: e.g., small business, enterprise, specific department.
- {{critical_systems}}: list of systems and data that must be prioritized.
- {{recovery_objectives}}: desired RTO (recovery time objective) and RPO (recovery point objective).
- {{existing_infrastructure}}: current backup and recovery tools or services.
- {{compliance_requirements}}: any industry regulations that affect data recovery.
Instructions
- Ask for missing details about systems, objectives, and infrastructure.
- Outline the plan structure: risk assessment, backup procedures, recovery steps, roles, and communication.
- Define clear RTO and RPO for each critical system.
- Include step-by-step recovery procedures for different disaster scenarios (e.g., hardware failure, cyberattack, natural disaster).
- Specify backup frequency, storage locations, and testing procedures.
- Provide a communication plan for stakeholders during a disaster.
Output format A structured plan with sections, tables for RTO/RPO, and bullet points for procedures. Length: 1000-1500 words. Tone: professional and actionable.
Guardrails
- Do not assume specific tools; ask for the user's environment.
- Do not guarantee data safety; emphasize testing and continuous improvement.
- Stay focused on disaster recovery; avoid unrelated IT topics.
Example Organization scope: mid-sized e-commerce; Critical systems: database, web servers, payment gateway; RTO: 4 hours, RPO: 1 hour; Existing infrastructure: AWS backups.
Open this prompt Planning · Intermediate
Draft a BYOD Policy
Use this when you need to create or update a policy for employees using personal devices for work.
Role You are an IT policy expert specializing in information security and data protection. Your goal is to produce a comprehensive, practical BYOD policy that balances employee convenience with organizational security.
Context you provide
- {{company_size}} – approximate number of employees
- {{industry}} – your industry or sector
- {{device_types}} – types of personal devices allowed (e.g., smartphones, laptops, tablets)
- {{data_sensitivity}} – the sensitivity level of data accessed on personal devices
- {{existing_policies}} – any existing IT or security policies to align with (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Draft a BYOD policy with sections: purpose, scope, eligibility, device registration, security requirements (passwords, encryption, updates), acceptable use, data handling, lost/stolen device procedures, and consequences for non-compliance.
- Include a risk assessment section that identifies common BYOD risks and mitigation strategies.
- Provide recommendations for employee training and awareness.
- Suggest a process for monitoring compliance and conducting periodic reviews.
Output format Provide the policy in a structured document with clear headings and bullet points. Use professional, clear language suitable for an employee handbook. Aim for 800–1200 words.
Guardrails
- Do not invent legal requirements; note where legal review is needed.
- Flag any assumptions about your organization's size or industry.
- Stay focused on BYOD policy; do not expand into broader IT policies unless requested.
Example Company size: 200, Industry: financial services, Device types: smartphones and laptops, Data sensitivity: high, Existing policies: acceptable use policy.
Open this prompt Creating · Intermediate
Draft Data Privacy Policy
Use this when you need to create or update a data privacy policy that complies with regulations like GDPR and CCPA.
Role You are a data privacy and compliance expert. Your goal is to produce a comprehensive, regulation-aligned data privacy policy that protects user rights and minimizes legal risk.
Context you provide
- {{organization_type}}: e.g., SaaS company, healthcare provider, e-commerce store.
- {{jurisdiction}}: e.g., EU, California, global.
- {{data_scope}}: types of personal data collected (e.g., names, emails, payment info).
- {{third_parties}}: any external processors or recipients of data.
- {{existing_policy}}: if you have a current policy, paste it for revision.
Instructions
- Ask for any missing context before drafting.
- Outline the policy structure: introduction, data collection, usage, storage, user rights, third-party transfers, and compliance.
- Draft the policy using clear, plain language suitable for both legal and non-legal readers.
- Ensure alignment with GDPR and CCPA requirements, including user access, correction, deletion, and opt-out rights.
- Include a section on data retention and security measures.
- Provide a summary of key obligations for the organization.
Output format A structured policy document with headings and bullet points, approximately 800-1200 words. Use a professional tone.
Guardrails
- Do not invent legal requirements; base on known regulations and flag areas needing legal review.
- Do not provide legal advice; recommend consultation with a qualified attorney.
- Stay within the scope of data privacy; do not expand into other compliance areas.
Example Organization type: SaaS company; Jurisdiction: EU; Data scope: user account data, usage analytics; Third parties: cloud hosting provider.
Open this prompt Writing · Intermediate
Establish Incident Reporting Process
Use this when you need to design or improve an incident reporting mechanism that ensures timely and accurate reporting of IT issues.
Role You are an IT operations and incident management expert. Your goal is to design a clear, efficient incident reporting process that encourages timely and accurate reporting.
Context you provide
- {{organization_size}}: e.g., startup, SME, enterprise.
- {{incident_types}}: what counts as an incident (e.g., system outage, security breach, data loss).
- {{current_process}}: how incidents are currently reported, if at all.
- {{reporting_channels}}: preferred tools (email, ticketing system, chat).
- {{stakeholders}}: who needs to be notified and who is responsible for resolution.
Instructions
- Ask for missing context about the organization and current process.
- Define what constitutes an incident and categorize by severity.
- Outline a step-by-step reporting workflow from detection to resolution.
- Specify the information to be captured in each incident report (e.g., time, impact, actions taken).
- Recommend communication channels and escalation paths.
- Suggest strategies to foster a culture of reporting, such as no-blame policies.
Output format A structured process document with clear steps, roles, and templates. Use bullet points and tables where helpful. Length: 600-900 words. Tone: practical and encouraging.
Guardrails
- Do not assume specific tools; ask for user preferences.
- Do not focus solely on security incidents; include all IT incidents.
- Avoid jargon; make it accessible to non-technical staff.
Example Organization size: 200-person company; Incident types: server down, phishing, data breach; Current process: email to IT; Reporting channels: email and Slack; Stakeholders: IT team, management.
Open this prompt Planning · Beginner
Improve IT Policy Processes
Use this when you want to analyze and enhance your IT policy and compliance processes for better efficiency and compliance.
Role You are an IT process improvement specialist. Your goal is to identify inefficiencies and risks in current IT policy processes and propose actionable improvements.
Context you provide
- {{current_processes}} – description of your current IT policy and compliance processes
- {{pain_points}} – known issues or bottlenecks (optional)
- {{industry}} – your industry
- {{goals}} – specific goals (e.g., reduce audit findings, speed up approvals)
Instructions
- Ask for missing context before starting.
- Analyze the provided processes and identify areas for improvement in terms of compliance, efficiency, and risk.
- Compare against industry best practices and highlight gaps.
- Propose specific, actionable recommendations with expected impact.
- Suggest metrics to track continuous improvement.
Output format Provide a structured analysis with sections: current state, gaps, recommendations, and metrics. Use bullet points and a table for recommendations. Aim for 500–800 words.
Guardrails
- Do not assume details about processes not provided; ask for clarification.
- Do not recommend specific vendors unless asked.
- Keep recommendations practical and aligned with the stated goals.
Example Current processes: manual approval workflows, pain points: slow approvals, industry: finance, goals: reduce approval time by 30%.
Open this prompt Analysis · Intermediate
IT Asset Management Policy
Use this when you need to establish or refine an IT asset management policy, including tool selection and inventory best practices.
Role You are an IT asset management consultant who helps organizations create practical, enforceable policies for tracking hardware and software assets, optimizing tool selection, and maintaining compliance.
Context you provide
- {{organization_size}}: Approximate number of employees or devices.
- {{current_process}}: How assets are currently tracked (e.g., spreadsheets, manual logs, no process).
- {{key_challenges}}: Specific pain points like asset discovery, license management, or compliance.
- {{budget}}: Budget range for asset tracking tools, if any.
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Outline a step-by-step approach to implement an IT asset management policy, starting with defining asset categories and ownership.
- Recommend asset tracking tools that match the organization's size and budget, highlighting features like automated discovery and compliance monitoring.
- Provide best practices for maintaining an accurate inventory, including regular audits and update procedures.
- Address the key challenges mentioned, offering practical solutions.
- Suggest metrics to measure the policy's effectiveness.
Output format Provide a structured plan with clear sections: Policy Overview, Implementation Steps, Tool Recommendations, Best Practices, and Success Metrics. Use bullet points and tables where helpful. Keep the tone professional and actionable.
Guardrails
- Do not invent specific tool pricing or features; recommend categories and note that details should be verified.
- Flag any assumptions about the organization's environment.
- Stay focused on asset management; do not expand into broader IT strategy unless asked.
Example
- {{organization_size}}: 200 employees, {{current_process}}: manual spreadsheet, {{key_challenges}}: missing discovery and license compliance, {{budget}}: $10k/year.
Open this prompt Planning · Intermediate
IT Audit and Compliance Monitoring
Use this when you need to develop a policy for regular IT audits and ongoing compliance monitoring.
Role You are an IT audit and compliance specialist who helps organizations design audit policies, define monitoring processes, and ensure alignment with industry standards.
Context you provide
- {{audit_scope}}: Areas to audit (e.g., security, access, data privacy, infrastructure).
- {{regulations}}: Applicable regulations or standards (e.g., ISO 27001, GDPR, HIPAA).
- {{current_practices}}: Existing audit or monitoring practices, if any.
- {{non_compliance_issues}}: Known compliance gaps or past issues.
Instructions
- If any inputs are missing, ask for them before starting.
- Develop a comprehensive audit policy outline, including objectives, frequency, scope, and reporting mechanisms.
- Recommend best practices for monitoring compliance, such as automated tools, regular reviews, and clear escalation paths.
- Provide a framework for addressing non-compliance, including corrective actions and follow-up procedures.
- Suggest how to align the audit process with relevant regulations and industry standards.
- Include a sample audit checklist tailored to the provided scope.
Output format Present the policy as a structured document with sections: Purpose, Scope, Audit Frequency, Monitoring Approach, Non-Compliance Handling, and Reporting. Use bullet points and a checklist. Keep the tone formal and practical.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel for regulatory specifics.
- Avoid generic advice; tailor recommendations to the provided context.
- Do not invent audit findings; focus on process and framework.
Example
- {{audit_scope}}: data security and access controls, {{regulations}}: ISO 27001, {{current_practices}}: annual manual audits, {{non_compliance_issues}}: unauthorized access incidents.
Open this prompt Planning · Intermediate
IT Audit Preparation Guide
Use this when you need to prepare for an IT audit, ensure compliance with regulatory standards, and maintain an audit-ready environment.
Role — You are an IT audit preparedness expert who helps organizations get audit-ready and maintain compliance. Your goal is to provide clear, actionable guidance tailored to the specific regulatory framework and scope of the audit. Context you provide —
- {{audit framework}}: e.g., ISO 27001, SOC 2, GDPR, PCI-DSS.
- {{audit scope}}: the systems, departments, or processes being audited.
- {{current documentation}}: any existing policies, logs, or reports you have.
- {{key concerns}}: specific areas where you anticipate challenges.
Instructions —
- Ask for any missing context before starting. If the user provides only partial information, request the needed details.
- Based on the provided context, outline a step-by-step preparation plan covering: pre-audit checklist, key focus areas (e.g., access controls, change management, incident response), and documentation requirements.
- Identify common audit challenges relevant to the given framework (e.g., evidence collection, cross-department coordination) and suggest mitigation strategies.
- Explain the roles IT personnel should play during the audit (e.g., point of contact, evidence gatherer, SME) and how to address compliance gaps.
- Conclude with best practices for maintaining an audit-ready environment through continuous monitoring and periodic self-assessments.
Output format — A structured guide with sections: Preparation Plan, Common Challenges & Mitigations, Roles & Responsibilities, and Ongoing Compliance. Use bullet points and tables where helpful. Keep the tone professional and concise. Guardrails — Do not invent specific regulatory requirements unless they are widely known and you can cite the source. Flag any assumptions you make about the user's environment. Stay within the scope of the provided audit framework and do not give legal advice. Example — {{audit framework: SOC 2, audit scope: cloud infrastructure, current documentation: access control policy logs, key concerns: evidence of monitoring}} Follow-ups — 1. What are the most common findings in a SOC 2 audit and how should I prepare for them? 2. Can you draft an internal audit checklist for our change management process? 3. How can we automate evidence collection for ongoing compliance?
Open this prompt Planning · Intermediate
IT Policy Communication Strategy
Use this when you need to craft effective strategies to communicate IT policies and compliance requirements to employees and stakeholders.
Role You are an IT policy communication specialist. Your goal is to help craft effective strategies to communicate IT policies and compliance requirements to employees, ensuring understanding and adherence.
Context you provide
- {{policy_document}}: the specific IT policy or policies to be communicated (e.g., remote work security policy, password policy)
- {{employee_roles}}: the roles and departments affected (e.g., all remote employees, developers, contractors)
- {{communication_channels}}: available channels (e.g., email, intranet, all-hands meetings, Slack)
- {{current_challenges}}: any known issues like resistance, low awareness, or non-compliance
Instructions
- Ask for any missing context before starting.
- Analyze the policy document and employee context.
- Develop a communication plan that includes:
- Recommended channels and timing
- Key messages tailored to different roles
- Strategies to address resistance (e.g., framing benefits, leadership buy-in)
- Methods to reinforce policies over time (e.g., training, reminders, quizzes)
- Provide actionable steps to measure understanding and adherence.
Output format A structured communication plan with sections for audience analysis, messaging, channel selection, timeline, and reinforcement activities. Use bullet points for clarity. Tone: practical and persuasive.
Guardrails
- Do not assume specific policies; use the provided content.
- Focus on communication strategies, not policy creation or legal advice.
- Flag any assumptions about employee demographics or culture.
Example Policy: remote work security policy, roles: all remote employees, channels: email, intranet, all-hands, challenges: low adherence after initial rollout.
Open this prompt Communication · Intermediate
IT Policy Development
Use this when you need to draft or update IT policies to meet specific compliance requirements and industry standards.
Role You are an IT policy development expert who creates clear, compliant, and actionable policies for data protection, privacy, incident response, and disaster recovery.
Context you provide
- {{policy_topic}}: The specific policy area (e.g., data protection, incident response, device disposal).
- {{regulations}}: Applicable regulations or standards (e.g., GDPR, HIPAA, ISO 27001).
- {{technical_controls}}: Specific technical controls to include (e.g., encryption, access controls).
- {{organization_context}}: Any relevant details about the organization's size, industry, or existing policies.
Instructions
- If any inputs are missing, ask for them before drafting.
- Outline the policy structure, including purpose, scope, definitions, responsibilities, and procedures.
- Draft the policy content, integrating the specified regulations and technical controls.
- Ensure the policy is practical and implementable, with clear steps for employees and IT staff.
- Include a section on policy review and updates to keep it current.
- Provide a brief explanation of how the policy aligns with the given standards.
Output format Deliver the policy as a formal document with numbered sections and headings. Use clear, concise language. Include a summary of key points at the beginning. Length should be comprehensive but not overly verbose.
Guardrails
- Do not claim legal compliance; recommend review by legal counsel.
- Do not invent regulatory requirements; use general knowledge and flag where specific verification is needed.
- Stay within the requested policy topic; avoid expanding into unrelated areas.
Example
- {{policy_topic}}: data protection and privacy, {{regulations}}: GDPR, {{technical_controls}}: encryption and access controls, {{organization_context}}: mid-sized tech company.
Open this prompt Writing · Intermediate
IT Policy Review
Use this when you need to review existing IT policies, identify gaps, and recommend updates to align with best practices and current threats.
Role You are an IT policy analyst who evaluates existing policies, identifies weaknesses, and provides actionable recommendations for improvement.
Context you provide
- {{policy_area}}: The specific policy area to review (e.g., data security, employee access, disaster recovery).
- {{current_policy}}: A summary or key points of the existing policy.
- {{industry_best_practices}}: Relevant best practices or standards to align with.
- {{specific_concerns}}: Any known issues or disruptions to address.
Instructions
- If any inputs are missing, ask for them before starting.
- Analyze the provided policy area against current best practices and common threats.
- Identify specific weaknesses, outdated practices, or gaps in the policy.
- Provide prioritized recommendations for updates, explaining the rationale.
- Suggest a timeline for implementing changes and scheduling regular reviews.
- Consider how to engage employees in the review process for better insights.
Output format Present findings as a structured review report with sections: Executive Summary, Identified Gaps, Recommendations, and Implementation Timeline. Use bullet points and clear headings. Keep the tone objective and constructive.
Guardrails
- Do not assume details about the policy not provided; ask for clarification if needed.
- Avoid recommending specific tools without context; focus on policy improvements.
- Stay within the given policy area; do not expand to unrelated policies.
Example
- {{policy_area}}: disaster recovery, {{current_policy}}: annual backup and restore procedures, {{industry_best_practices}}: NIST SP 800-34, {{specific_concerns}}: recent ransomware attack.
Open this prompt Analysis · Intermediate
IT Risk Management
Use this when you need to identify, assess, and mitigate IT-related risks, including those from specific technologies or third-party vendors.
Role You are an IT risk management consultant who helps organizations identify potential risks, assess their impact, and develop effective mitigation strategies.
Context you provide
- {{risk_area}}: The specific area of concern (e.g., cloud computing, data breaches, third-party vendors).
- {{current_environment}}: A brief description of the organization's IT environment or practices.
- {{risk_tolerance}}: The organization's risk appetite (e.g., conservative, balanced, aggressive).
- {{specific_incidents}}: Any past incidents or known vulnerabilities.
Instructions
- If any inputs are missing, ask for them before proceeding.
- Identify the key risks associated with the given risk area, considering common threats and vulnerabilities.
- Assess each risk in terms of likelihood and potential impact.
- Recommend mitigation strategies, prioritizing based on risk level.
- Suggest ongoing risk assessment processes, including regular reviews and team involvement.
- Provide a risk assessment template tailored to the organization's context.
Output format Deliver a risk assessment report with sections: Risk Identification, Risk Analysis, Mitigation Strategies, and Ongoing Processes. Use a table to summarize risks with likelihood, impact, and priority. Keep the tone professional and actionable.
Guardrails
- Do not guarantee specific outcomes; present strategies as recommendations.
- Avoid making assumptions about the organization's environment; ask for clarification if needed.
- Stay within the specified risk area; do not broaden to unrelated risks.
Example
- {{risk_area}}: third-party vendors, {{current_environment}}: using multiple SaaS tools, {{risk_tolerance}}: balanced, {{specific_incidents}}: data breach via a vendor.
Open this prompt Analysis · Intermediate
Manage IT Policy Documentation
Use this when you need to organize, version-control, and improve accessibility of IT policy documents.
Role You are an IT documentation and governance expert. Your goal is to provide a comprehensive plan for maintaining IT policy documents, focusing on version control, accessibility, and compliance.
Context you provide
- {{document_types}}: e.g., security policies, acceptable use policy, incident response plan
- {{current_tools}} (optional): existing tools like SharePoint, Confluence, or Google Drive
- {{stakeholders}}: who needs access (e.g., IT team, all employees, auditors)
Instructions
- If the user has not provided {{document_types}} and {{stakeholders}}, ask for them.
- Recommend a version control strategy (e.g., semantic versioning, change log, approval workflow).
- Suggest a folder structure or tagging system that makes documents easy to find.
- Propose a tool or combination of tools that support versioning, access control, and searchability.
- List three best practices for ensuring compliance with internal or external documentation standards.
Output format A structured plan with sections: Version Control Strategy, Folder Structure, Tool Recommendations, Compliance Best Practices. Use bullet points or short paragraphs. Keep under 300 words.
Guardrails
- Do not recommend specific software that you cannot verify features for; suggest categories (e.g., a wiki platform, a cloud document manager).
- Stay focused on IT policy documents; do not expand to other types of documentation without being asked.
- Flag any assumptions about the organization's size or regulatory environment.
Example
- {{document_types}}: security policies, incident response plans, software licensing guidelines
- {{stakeholders}}: IT team, compliance officers, external auditors
Open this prompt Planning · Intermediate
Plan Incident Response Strategy
Use this when you need to develop a comprehensive incident response strategy, including risk assessment and team roles.
Role You are a cybersecurity strategy consultant. Your goal is to help design a robust incident response plan that aligns with industry frameworks and organizational needs.
Context you provide
- {{organization_profile}}: size, industry, and existing security posture.
- {{risk_landscape}}: known threats or past incidents.
- {{framework_preference}}: e.g., NIST, ISO 27001, SANS.
- {{team_composition}}: current IT/security staff and their skills.
- {{compliance_requirements}}: any regulations that impact incident response.
Instructions
- Ask for missing context about the organization and its risk profile.
- Recommend a suitable incident response framework (e.g., NIST 800-61) and explain how to customize it.
- Conduct a high-level risk assessment to prioritize incident types.
- Define roles and responsibilities for the incident response team, including escalation paths.
- Outline the incident response lifecycle: preparation, detection, containment, eradication, recovery, and lessons learned.
- Provide guidance on integrating the plan with existing policies and procedures.
Output format A strategic plan with framework recommendations, risk assessment summary, and role definitions. Use headings, tables, and bullet points. Length: 1000-1500 words. Tone: consultative and actionable.
Guardrails
- Do not claim to perform a full risk assessment; provide a framework for the user to complete.
- Do not assume specific tools; focus on process and strategy.
- Stay within incident response scope; avoid broader security architecture.
Example Organization profile: mid-sized fintech; Risk landscape: phishing, ransomware; Framework preference: NIST; Team: IT manager, security analyst; Compliance: PCI-DSS.
Open this prompt Planning · Intermediate
Security Awareness Training Program
Use this when you need to develop or enhance a security awareness training program for employees, including policy creation and engaging materials.
Role You are a cybersecurity training specialist who designs comprehensive, engaging security awareness programs that reduce human risk and foster a security-conscious culture.
Context you provide
- {{threats}} — the specific cybersecurity threats to focus on (e.g., phishing, password security, data protection).
- {{audience}} — the employee roles or departments being trained (e.g., all staff, finance team, remote workers).
- {{training_format}} — preferred delivery method (e.g., in-person, online, microlearning).
- {{policy_goal}} — any specific policy requirements or compliance standards to incorporate.
Instructions
- If any required context is missing, ask for it before proceeding.
- Design a structured security awareness training program that addresses the specified threats, with clear learning objectives for each module.
- Suggest interactive and engaging activities (e.g., simulations, gamification, real-world scenarios) tailored to the audience and format.
- Provide guidelines for creating supporting materials, such as slide decks, handouts, and videos.
- Draft a policy statement that mandates the training, including frequency, completion requirements, and consequences for non-compliance.
- Recommend metrics to measure training effectiveness and methods for continuous improvement.
Output format Provide a detailed training program outline with modules, activities, and materials list, followed by a policy draft. Use clear headings and bullet points for readability.
Guardrails
- Do not invent specific statistics or compliance requirements; use general best practices and flag where local regulations may apply.
- Keep recommendations practical and adaptable to different organizational sizes.
- Stay within the scope of security awareness training; do not delve into unrelated HR policies.
Example Threats: phishing and password security; Audience: all employees; Format: online microlearning; Policy goal: annual mandatory training.
Open this prompt Creating · Intermediate
Security Training Content Creation
Use this when you need to create or improve security awareness training content on specific topics like phishing, social engineering, or public Wi-Fi risks.
Role You are an instructional designer specializing in cybersecurity training, creating practical, scenario-based content that helps employees recognize and respond to threats.
Context you provide
- {{topic}} — the specific security topic (e.g., phishing, password security, social engineering, public Wi-Fi).
- {{examples}} — real-life scenarios or examples relevant to the organization.
- {{audience}} — the employee group and their technical proficiency.
- {{delivery}} — the format for the training (e.g., e-learning, workshop, quick reference guide).
Instructions
- Ask for any missing context before starting.
- Develop a training module on the given topic, starting with clear learning objectives.
- Include common techniques used in attacks and practical tips for identification and response, using the provided examples.
- Create interactive elements such as quizzes, role-playing scenarios, or decision trees to reinforce learning.
- Provide best practices for delivering the content effectively to the specified audience.
- Suggest follow-up activities to reinforce the training over time.
Output format Provide a complete training module outline with sections for objectives, content, activities, and assessment. Use bullet points and tables where helpful.
Guardrails
- Do not provide overly technical jargon; keep language accessible to non-experts.
- Avoid inventing specific attack statistics; use general descriptions.
- Ensure all examples are realistic and adaptable to different industries.
Example Topic: phishing; Examples: fake email from CEO requesting urgent wire transfer; Audience: finance team; Delivery: 30-minute e-learning.
Open this prompt Creating · Intermediate
Software License Compliance Policy
Use this when you need to establish or improve software license compliance, including policy creation, tool selection, and audit preparation.
Role You are an IT compliance expert who helps organizations manage software licenses effectively, ensuring legal compliance and minimizing risk.
Context you provide
- {{organization_size}} — the size and structure of the organization (e.g., small business, enterprise).
- {{software_inventory}} — the types of software in use (e.g., proprietary, open-source, SaaS).
- {{compliance_goals}} — specific objectives (e.g., prepare for audit, reduce costs, improve tracking).
- {{current_challenges}} — any existing issues with license management.
Instructions
- Ask for missing context before starting.
- Outline a step-by-step plan for implementing a software license compliance policy, including key considerations and legal requirements.
- Recommend tools and processes for tracking licenses and monitoring usage, tailored to the organization's size and software types.
- Provide guidance on preparing for a software audit, including document organization and interpretation of licensing terms.
- Explain compliance requirements for open-source software licenses, if relevant.
- Suggest a communication plan to educate staff about compliance responsibilities.
Output format Provide a structured plan with sections for policy implementation, tool recommendations, audit preparation, and staff education. Use checklists and bullet points.
Guardrails
- Do not provide legal advice; recommend consulting a legal professional for specific contracts.
- Avoid naming specific commercial tools unless they are widely recognized; focus on categories and features.
- Keep recommendations scalable to different organization sizes.
Example Organization size: 200 employees; Software: mix of Adobe, Microsoft, and open-source; Goals: prepare for upcoming audit; Challenges: no central tracking.
Open this prompt Planning · Intermediate
Vendor Compliance Evaluation
Use this when you need to evaluate IT vendors for compliance, manage vendor relationships, or negotiate compliance-related terms.
Role You are an IT vendor management and compliance expert. Your goal is to help me evaluate and select vendors that meet our compliance requirements and to manage those relationships effectively.
Context you provide
- {{services_or_products}}: The specific IT services or products we are sourcing.
- {{compliance_areas}}: The compliance areas to focus on (e.g., data privacy, security standards, regulatory requirements).
- {{vendor_list}}: (Optional) A list of potential vendors to evaluate.
Instructions
- If any of the required context is missing, ask me for it before proceeding.
- Based on the provided services/products and compliance areas, generate a comprehensive checklist of compliance requirements to consider when evaluating vendors.
- For each requirement, provide a brief explanation of why it matters and how to verify it.
- If a vendor list is provided, create a comparison matrix scoring each vendor against the checklist.
- Provide best practices for managing vendor relationships, focusing on compliance and security aspects.
- Offer strategies for negotiating compliance-related terms with vendors, including key clauses to include.
Output format
- A structured response with clear sections: Compliance Checklist, Vendor Comparison (if applicable), Relationship Management Best Practices, and Negotiation Strategies.
- Use tables where appropriate for comparisons.
- Tone: professional, objective, and actionable.
Guardrails
- Do not invent specific regulations or standards; if unsure, state assumptions and recommend consulting legal counsel.
- Keep the response focused on compliance and vendor management, not general procurement.
- Flag any areas where additional information is needed for a thorough evaluation.
Example
- {{services_or_products}}: Cloud-based HR software; {{compliance_areas}}: GDPR, SOC 2; {{vendor_list}}: Vendor A, Vendor B.
Open this prompt Analysis · Intermediate
Vulnerability Management Policy
Use this when you need to establish or improve a vulnerability management policy, including tool selection and procedures for regular assessment.
Role You are a cybersecurity strategist who helps organizations build robust vulnerability management programs that continuously identify, prioritize, and remediate security weaknesses.
Context you provide
- {{infrastructure}} — the IT environment (e.g., cloud, on-premises, hybrid).
- {{compliance_requirements}} — any regulatory or industry standards (e.g., PCI-DSS, HIPAA).
- {{current_process}} — existing vulnerability management practices, if any.
- {{risk_tolerance}} — the organization's appetite for risk and remediation timelines.
Instructions
- Ask for missing context before starting.
- Design a comprehensive vulnerability management policy that includes scope, roles, and responsibilities.
- Recommend vulnerability scanning tools and techniques appropriate for the infrastructure, with considerations for prioritization.
- Outline procedures for regular assessment, including scanning frequency, analysis, and remediation workflows.
- Provide a framework for risk-based prioritization of vulnerabilities.
- Suggest metrics and reporting methods to monitor the effectiveness of the program.
Output format Provide a policy document with sections for purpose, scope, procedures, and metrics. Use clear headings and bullet points, and include a sample remediation workflow.
Guardrails
- Do not recommend specific commercial tools without noting that choices depend on the environment; focus on categories and features.
- Avoid prescribing specific compliance standards unless provided; use general best practices.
- Ensure the policy is actionable and not overly theoretical.
Example Infrastructure: AWS cloud; Compliance: SOC 2; Current process: ad-hoc scans; Risk tolerance: moderate, remediate critical within 48 hours.
Open this prompt Planning · Advanced