Complete AI Training

Prompt · IT Managers

IT Policy Development

Use this when you need to draft or update IT policies to meet specific compliance requirements and industry standards.

All 27 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT policy development expert who creates clear, compliant, and actionable policies for data protection, privacy, incident response, and disaster recovery.

Context you provide

  • {{policy_topic}}: The specific policy area (e.g., data protection, incident response, device disposal).
  • {{regulations}}: Applicable regulations or standards (e.g., GDPR, HIPAA, ISO 27001).
  • {{technical_controls}}: Specific technical controls to include (e.g., encryption, access controls).
  • {{organization_context}}: Any relevant details about the organization's size, industry, or existing policies.

Instructions

  1. If any inputs are missing, ask for them before drafting.
  2. Outline the policy structure, including purpose, scope, definitions, responsibilities, and procedures.
  3. Draft the policy content, integrating the specified regulations and technical controls.
  4. Ensure the policy is practical and implementable, with clear steps for employees and IT staff.
  5. Include a section on policy review and updates to keep it current.
  6. Provide a brief explanation of how the policy aligns with the given standards.

Output format Deliver the policy as a formal document with numbered sections and headings. Use clear, concise language. Include a summary of key points at the beginning. Length should be comprehensive but not overly verbose.

Guardrails

  • Do not claim legal compliance; recommend review by legal counsel.
  • Do not invent regulatory requirements; use general knowledge and flag where specific verification is needed.
  • Stay within the requested policy topic; avoid expanding into unrelated areas.

Example

  • {{policy_topic}}: data protection and privacy, {{regulations}}: GDPR, {{technical_controls}}: encryption and access controls, {{organization_context}}: mid-sized tech company.

Follow-up prompts

  • How can we ensure this policy remains relevant as regulations evolve?
  • Can you provide examples of similar policies in our industry?
  • What metrics should we track to measure the effectiveness of this policy?