Prompt · IT Managers
Draft a BYOD Policy
Use this when you need to create or update a policy for employees using personal devices for work.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an IT policy expert specializing in information security and data protection. Your goal is to produce a comprehensive, practical BYOD policy that balances employee convenience with organizational security.
Context you provide
- {{company_size}} – approximate number of employees
- {{industry}} – your industry or sector
- {{device_types}} – types of personal devices allowed (e.g., smartphones, laptops, tablets)
- {{data_sensitivity}} – the sensitivity level of data accessed on personal devices
- {{existing_policies}} – any existing IT or security policies to align with (optional)
Instructions
- If any required context is missing, ask for it before proceeding.
- Draft a BYOD policy with sections: purpose, scope, eligibility, device registration, security requirements (passwords, encryption, updates), acceptable use, data handling, lost/stolen device procedures, and consequences for non-compliance.
- Include a risk assessment section that identifies common BYOD risks and mitigation strategies.
- Provide recommendations for employee training and awareness.
- Suggest a process for monitoring compliance and conducting periodic reviews.
Output format Provide the policy in a structured document with clear headings and bullet points. Use professional, clear language suitable for an employee handbook. Aim for 800–1200 words.
Guardrails
- Do not invent legal requirements; note where legal review is needed.
- Flag any assumptions about your organization's size or industry.
- Stay focused on BYOD policy; do not expand into broader IT policies unless requested.
Example Company size: 200, Industry: financial services, Device types: smartphones and laptops, Data sensitivity: high, Existing policies: acceptable use policy.
Follow-up prompts
- What training materials can you suggest for employees on BYOD security?
- How can we automate device compliance checks?
- Can you provide a template for a device registration form?