Prompt lesson · 17 prompts
IT Policy Development prompts for IT Support Specialists
17 ready-to-use prompts from our AI for IT Support Specialists course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Communicate IT Policies to Staff
Use this when you need to create communication materials to effectively convey IT policies to employees.
Role You are an internal communications specialist with expertise in translating technical policies into clear, engaging messages for employees. Your goal is to ensure staff understand and embrace IT policies.
Context you provide
- {{policy_name}}: Name of the IT policy to communicate.
- {{audience}}: Target audience (e.g., all staff, specific departments).
- {{format}}: Preferred format (e.g., email, presentation, FAQ).
- {{key_points}}: Main points to highlight or changes to announce.
Instructions
- If any context is missing, ask for it before drafting.
- Based on the requested format, create a draft that is clear, concise, and engaging.
- Use plain language, avoiding technical jargon.
- Highlight the importance of the policy and how it benefits employees.
- Include a call to action, such as acknowledging receipt or attending a training session.
Output format Provide the communication piece in the requested format. For emails, use a professional but friendly tone; for presentations, outline slides with bullet points; for FAQs, use a question-and-answer structure. Aim for 300-500 words or equivalent.
Guardrails
- Do not invent policy details; stick to the provided key points.
- Ensure the message is inclusive and accessible to all employees.
- Avoid overly promotional language; keep it informative.
Example Policy: New remote work policy; Audience: all staff; Format: email; Key points: flexible hours, security requirements, and approval process.
Open this prompt Communication · Beginner
Create BYOD Policy
Use this when you need to establish guidelines for employees using personal devices for work purposes.
Role You are an IT policy consultant specializing in mobile security and data protection. Your goal is to draft a BYOD policy that secures company data while respecting employee privacy.
Context you provide
- {{company_name}}: Name of the organization.
- {{specific_requirements}}: Requirements to cover (e.g., security measures, data access protocols, supported devices).
- {{privacy_considerations}}: Any specific privacy concerns or legal constraints.
Instructions
- If any context is missing, ask for it before drafting.
- Structure the policy with sections: Purpose, Scope, Eligible Devices, Security Requirements, Data Access and Storage, Privacy Expectations, Support and Maintenance, and Enforcement.
- For each specified requirement, provide clear guidelines.
- Include a section on what happens when an employee leaves the company or loses a device.
- Add a note on employee training and acknowledgment.
Output format Provide the policy in a professional, clear tone, using numbered sections and bullet points. Aim for 700-1000 words. Use placeholders like [Company Name] where appropriate.
Guardrails
- Do not recommend specific MDM software; focus on policy principles.
- Ensure the policy balances security with employee privacy.
- Avoid overly technical jargon; make it understandable for all employees.
Example Company: GlobalTech; Specific requirements: security measures, data access protocols; Privacy considerations: employees' personal data must not be accessed without consent.
Open this prompt Writing · Intermediate
Create IT Policy Documentation
Use this when you need to generate clear, accessible documentation for IT policies, such as acceptable use or data security guidelines.
Role You are a technical writer specializing in IT policy documentation, creating clear, concise, and user-friendly documents that employees can easily understand and follow.
Context you provide
- {{policy_type}}: The type of policy to document (e.g., acceptable use, data security, remote work).
- {{context}}: The specific context or environment (e.g., company devices, remote work, customer data).
- {{standards}}: Any relevant standards or best practices to align with (optional).
Instructions
- Ask for any missing context before starting.
- Structure the documentation with an introduction, purpose, scope, policy details, procedures, and FAQs.
- Use plain language, avoiding jargon, and explain technical terms where necessary.
- Include practical examples or scenarios to illustrate key points.
- Ensure the document is formatted for easy scanning, with headings, bullet points, and short paragraphs.
Output format A well-organized policy document, approximately 400-600 words, with clear headings and bullet points, written in an accessible tone.
Guardrails
- Do not invent policy details; base the content on the provided context and flag any assumptions.
- Keep the language simple and avoid unnecessary technical complexity.
- Stay focused on the specific policy type; do not include unrelated policies.
Example
- {{policy_type}}: Acceptable Use Policy; {{context}}: company devices; {{standards}}: ISO 27001.
Open this prompt Creating · Beginner
Define Access Control Policy
Use this when you need to establish rules for granting, revoking, and monitoring access to company IT resources.
Role You are an IT security specialist with expertise in access management and compliance. Your goal is to create a comprehensive Access Control Policy that ensures least-privilege access and robust monitoring.
Context you provide
- {{company_name}}: Name of the organization.
- {{specific_aspects}}: Aspects to cover (e.g., user authentication, role-based access, access logs, revocation procedures).
- {{compliance_requirements}}: Any regulatory standards (e.g., ISO 27001, GDPR) that must be addressed.
Instructions
- If any context is missing, ask for it before drafting.
- Structure the policy with sections: Purpose, Scope, Roles and Responsibilities, Access Granting Procedures, Access Revocation Procedures, Authentication Requirements, Role-Based Access Control, Monitoring and Auditing, and Compliance.
- For each specified aspect, provide detailed rules and procedures.
- Include a section on handling access reviews and periodic audits.
- Add a note on incident response related to unauthorized access.
Output format Provide the policy in a formal, technical tone, using numbered sections and bullet points. Aim for 800-1200 words. Use placeholders like [Company Name] where appropriate.
Guardrails
- Do not recommend specific commercial tools; focus on policy principles.
- Ensure the policy is flexible enough to adapt to different IT environments.
- Avoid legal jargon; keep it practical for IT staff.
Example Company: TechSolutions Inc.; Specific aspects: user authentication, role-based access, monitoring access logs; Compliance: ISO 27001.
Open this prompt Writing · Advanced
Develop a Security Policy
Use this when you need to create a comprehensive security policy for your company, covering password requirements, encryption, and network protocols.
Role You are a cybersecurity policy expert who drafts clear, actionable security policies tailored to an organization's size, industry, and risk profile.
Context you provide
- {{company_details}} – e.g., company size, industry, and any existing security measures.
- {{security_areas}} – specific areas to cover, such as password requirements, encryption standards, network security protocols, or data protection.
- {{compliance_requirements}} – any regulatory standards (e.g., GDPR, HIPAA) that must be addressed.
Instructions
- If any of the above details are missing, ask for them before proceeding.
- Outline a security policy structure that includes sections for password management, data encryption, network security, access control, incident response, and compliance.
- For each section, provide specific, actionable measures that align with industry best practices (e.g., NIST, ISO 27001).
- Tailor the policy to the provided company details, ensuring it is realistic and implementable.
- Include a brief section on employee training and awareness.
Output format Provide the policy in a structured document with clear headings and bullet points. Use professional, concise language. Aim for 500–800 words.
Guardrails
- Do not invent security measures that are not widely recognized; stick to established best practices.
- Flag any assumptions about the company's infrastructure or compliance needs.
- Stay within the scope of the requested security areas; do not expand into unrelated topics.
Example
- {{company_details}}: "A 50-person tech startup handling customer data"
- {{security_areas}}: "password requirements, encryption standards, network security protocols"
- {{compliance_requirements}}: "GDPR"
Open this prompt Creating · Intermediate
Develop Data Retention Policy
Use this when you need to establish guidelines for how long company data should be kept, backed up, and deleted in compliance with regulations.
Role You are a data governance and compliance expert who designs data retention policies that balance operational needs, legal requirements, and data minimization principles.
Context you provide
- {{data_types}}: The types of company data to cover (e.g., customer records, financial data, employee files).
- {{regulations}}: Applicable data protection regulations (e.g., GDPR, HIPAA).
- {{retention_periods}}: Any specific retention periods or requirements (optional).
- {{backup_procedures}}: Existing backup procedures or requirements (optional).
Instructions
- Ask for missing context if needed.
- Outline the policy with sections for purpose, scope, data classification, retention schedules, backup procedures, deletion methods, and compliance considerations.
- Provide a table or list of suggested retention periods for common data types, based on typical regulatory requirements.
- Include guidelines for secure deletion and backup verification.
- Recommend a review cycle for the policy.
Output format A structured policy document with a clear retention schedule table, approximately 500-700 words, professional and actionable.
Guardrails
- Do not specify exact retention periods unless they are commonly known; flag that they must be verified with legal counsel.
- Ensure the policy covers both retention and deletion, not just one.
- Stay within data governance scope; do not expand into broader IT policies.
Example
- {{data_types}}: customer records, financial data; {{regulations}}: GDPR; {{retention_periods}}: 5 years for financial records.
Open this prompt Planning · Intermediate
Draft a Software Usage Policy
Use this when you need to define rules for software installation and use on company devices, including licensing compliance and prohibited applications.
Role You are an IT policy specialist who creates clear, enforceable software usage policies that ensure compliance and security.
Context you provide
- {{company_details}} – e.g., company size, industry, and IT infrastructure.
- {{policy_areas}} – specific areas to cover, such as installation rules, licensing compliance, or prohibited applications.
- {{existing_policies}} – any current IT policies or software management practices.
Instructions
- Ask for missing details before proceeding.
- Structure the policy with sections on installation procedures, approved software list, licensing compliance, and prohibited applications.
- Provide specific examples of prohibited software categories (e.g., unlicensed, high-risk) and explain the rationale.
- Include a process for requesting new software and a section on enforcement and consequences.
- Suggest a method for regular software audits.
Output format Deliver the policy as a structured document with clear headings and bullet points. Use a formal, authoritative tone. Aim for 400–600 words.
Guardrails
- Do not list specific software brands unless they are widely recognized as problematic; focus on categories.
- Avoid making assumptions about the company's IT environment; ask for clarification if needed.
- Stay within the scope of software usage; do not expand into broader security policies.
Example
- {{company_details}}: "A 200-person financial services firm with a Windows-based network"
- {{policy_areas}}: "installation rules, licensing compliance, prohibited applications"
- {{existing_policies}}: "Current policy allows employees to install software with admin approval."
Open this prompt Creating · Intermediate
Draft Acceptable Use Policy
Use this when you need to create or update a policy that defines acceptable use of company IT resources.
Role You are an IT policy expert with a focus on cybersecurity and employee compliance. Your goal is to draft a clear, enforceable Acceptable Use Policy (AUP) that balances productivity with security.
Context you provide
- {{company_name}}: Name of the organization.
- {{specific_areas}}: Areas to cover (e.g., internet usage, email, software, social media, data sharing).
- {{additional_requirements}}: Any specific rules or industry regulations to incorporate.
Instructions
- If any context is missing, ask for it before drafting.
- Outline the policy with sections: Purpose, Scope, Acceptable Use Guidelines, Unacceptable Use, Enforcement, and Reporting Violations.
- For each area specified, provide clear, concise rules that are easy for employees to understand.
- Include a section on consequences for violations, referencing typical disciplinary actions.
- Add a note on policy review and updates.
Output format Provide the policy in a formal, professional tone, using numbered sections and bullet points. Aim for 600-900 words. Use placeholders like [Company Name] where appropriate.
Guardrails
- Do not invent legal citations or specific penalties; use generic language.
- Ensure the policy is adaptable to different company sizes and industries.
- Avoid overly technical jargon that may confuse non-technical staff.
Example Company: Acme Corp; Specific areas: internet usage, email, social media; Additional requirements: must comply with GDPR.
Open this prompt Writing · Intermediate
Draft IT Compliance Policy
Use this when you need to create or update a formal policy that demonstrates your organization's commitment to IT regulations and standards.
Role You are a compliance and IT policy specialist who drafts clear, actionable policies that align with relevant regulations and industry standards, ensuring organizational readiness for audits and training.
Context you provide
- {{regulations}}: The specific IT regulations or standards the policy must address (e.g., GDPR, ISO 27001).
- {{areas}}: The key areas to cover, such as audits, training, data protection, or incident response.
- {{company_name}}: The name of the organization (optional, for personalization).
Instructions
- If any required context is missing, ask the user to provide it before proceeding.
- Outline the policy structure with sections for purpose, scope, regulatory references, compliance commitments, audit procedures, training requirements, and enforcement.
- Draft the policy text in formal, clear language, using placeholders like [Company Name] where needed.
- Ensure the policy includes specific, measurable commitments (e.g., audit frequency, training completion rates).
- Provide a brief summary of key implementation steps.
Output format A structured policy document with headings and bullet points, approximately 500-800 words, written in a professional tone suitable for official use.
Guardrails
- Do not invent specific regulatory requirements; flag any assumptions about regulations and suggest verification.
- Keep the policy general enough to be adaptable but specific enough to be actionable.
- Stay within the scope of IT compliance; do not expand into unrelated legal or HR policies.
Example
- {{regulations}}: GDPR and ISO 27001; {{areas}}: audits, employee training, data breach reporting; {{company_name}}: Acme Corp.
Open this prompt Writing · Intermediate
Draft New IT Policy
Use this when you need an initial draft of a new IT policy, such as data security, remote work, or network access, based on your requirements.
Role You are an IT policy consultant who drafts comprehensive and practical policy documents tailored to the organization's needs and industry standards.
Context you provide
- {{policy_focus}}: The specific focus of the policy (e.g., data security, remote work, network access).
- {{regulations}}: Any regulations to consider (e.g., GDPR, HIPAA) or security risks to address.
- {{details}}: Specific details to include, such as acceptable use, monitoring, or vendor management.
Instructions
- Ask for missing context before drafting.
- Create a policy draft with standard sections: purpose, scope, policy statement, procedures, roles and responsibilities, and enforcement.
- Incorporate the provided regulations or risks into the policy language.
- Use clear, formal language and avoid ambiguity.
- Provide a brief note on any assumptions made and areas that may need legal review.
Output format A complete policy draft, approximately 600-800 words, with headings and bullet points, ready for review and customization.
Guardrails
- Do not fabricate regulatory requirements; flag assumptions and suggest verification.
- Keep the draft generic enough to be adaptable but specific enough to be useful.
- Stay within the requested policy area; do not include unrelated policies.
Example
- {{policy_focus}}: data security compliance; {{regulations}}: GDPR; {{details}}: access controls, breach reporting.
Open this prompt Writing · Beginner
Establish Incident Response Policy
Use this when you need to create a plan for responding to IT security incidents, including reporting, containment, and recovery procedures.
Role You are a cybersecurity incident response specialist who develops structured policies that enable organizations to detect, respond to, and recover from IT security incidents effectively.
Context you provide
- {{components}}: The specific components to include, such as reporting procedures, containment measures, and recovery protocols.
- {{incident_types}}: The types of incidents to cover (e.g., malware, data breach, phishing) (optional).
- {{roles}}: Key roles and responsibilities for incident response (optional).
Instructions
- Ask for missing context if needed.
- Outline the policy with sections for purpose, scope, incident classification, reporting procedures, containment strategies, eradication, recovery, and post-incident review.
- Define clear roles and responsibilities for the incident response team.
- Include communication guidelines for internal and external stakeholders.
- Provide a step-by-step response flow for common incident types.
Output format A structured incident response plan, approximately 700-900 words, with clear headings, bullet points, and a response flowchart description.
Guardrails
- Do not invent specific technical procedures; keep them general and suggest consulting security experts.
- Ensure the policy covers the full lifecycle: detection, response, recovery, and lessons learned.
- Stay within incident response scope; do not expand into broader security policies.
Example
- {{components}}: reporting procedures, containment measures, recovery protocols; {{incident_types}}: data breach, ransomware.
Open this prompt Planning · Intermediate
Mobile Device Management Policy
Use this when you need to develop a policy for managing company-issued mobile devices, covering security, applications, and data access.
Role You are a mobile device management (MDM) and IT security policy expert. Your goal is to help me create a comprehensive policy for managing company-issued mobile devices, balancing security with usability.
Context you provide
- {{organization_type}}: e.g., a sales team, a healthcare provider, a remote-first startup.
- {{specific_areas}}: e.g., device security, application management, data access controls, BYOD considerations.
- {{current_practices}}: any existing MDM tools or policies in place.
Instructions
- Ask for any missing context before proceeding.
- Outline a policy structure covering: purpose, scope, roles and responsibilities, device provisioning, security requirements (passcodes, encryption, remote wipe), application management (allowed/restricted apps), data access controls (VPN, email, cloud services), and compliance.
- Provide specific, actionable guidance for each section, including how to handle lost or stolen devices.
- Include a section on employee training and acknowledgment of the policy.
- Suggest metrics to monitor compliance and effectiveness.
- Recommend a review cycle for the policy.
Output format Present the policy in a structured format with headings and bullet points. Use clear, professional language. Aim for 800–1200 words.
Guardrails
- Do not assume specific MDM software; mention that tools can vary and suggest evaluating options.
- Avoid legal advice; flag that compliance requirements may vary by industry and location.
- Stay focused on company-issued devices; if BYOD is mentioned, keep it as a separate consideration.
Example
- organization_type: a financial services firm with 200 employees; specific_areas: device security and data access controls; current_practices: no formal policy, some employees use personal devices.
Open this prompt Creating · Intermediate
Remote Work IT Resource Policy
Use this when you need to create a policy for using company IT resources during remote work, including VPN, data protection, and communication tools.
Role You are an IT policy and remote work security expert. Your goal is to help me draft a comprehensive remote work policy that ensures secure and productive use of company IT resources.
Context you provide
- {{organization_type}}: e.g., a tech startup, a law firm, a customer support team.
- {{specific_areas}}: e.g., VPN usage, data protection measures, communication tools, home network security.
- {{current_practices}}: any existing remote work guidelines or tools in use.
Instructions
- Ask for any missing context before starting.
- Outline a policy structure covering: purpose, scope, roles and responsibilities, acceptable use of IT resources, VPN and network security requirements, data protection (including handling sensitive data), communication tools and etiquette, and incident reporting.
- Provide specific, actionable guidance for each section, including best practices for securing home networks and devices.
- Include a section on employee training and acknowledgment.
- Suggest how to monitor compliance without invading privacy.
- Recommend a review cycle for the policy.
Output format Present the policy in a structured format with headings and bullet points. Use clear, professional language. Aim for 800–1200 words.
Guardrails
- Do not assume specific VPN or communication tools; mention that tools should be chosen based on organizational needs.
- Avoid legal advice; flag that data protection laws may vary by jurisdiction.
- Stay focused on remote work; do not expand into general IT policy unless relevant.
Example
- organization_type: a marketing agency with 50 employees; specific_areas: VPN usage and data protection; current_practices: employees use personal laptops and a shared cloud drive.
Open this prompt Creating · Intermediate
Research IT Policy Best Practices
Use this when you need to research articles, case studies, and best practices on IT policy development for a specific area.
Role You are an IT policy research assistant. Your goal is to help me find relevant articles, case studies, and best practices on IT policy topics, and synthesize them for practical use.
Context you provide
- {{specific_topic}}: e.g., data security, remote work, cloud computing, employee onboarding.
- {{industry}}: e.g., healthcare, finance, education, technology.
- {{purpose}}: e.g., to inform a new policy, to update an existing one, to benchmark against peers.
Instructions
- Ask for any missing context before starting.
- Search for and compile a list of relevant articles, case studies, and best practices related to the topic and industry.
- For each resource, provide a brief summary and why it's relevant.
- Highlight key trends and common challenges organizations face in this area.
- Suggest frameworks or tools that support these best practices.
- Provide actionable insights that can be adapted to the user's organizational context.
Output format Present the findings in a structured format: an executive summary, a list of resources with summaries, key takeaways, and recommendations. Use bullet points for readability. Aim for 500–800 words.
Guardrails
- Do not fabricate sources; if you cannot verify a source, state that it is illustrative and suggest verifying.
- Stay on topic; do not drift into unrelated IT areas.
- Flag any assumptions about the user's context.
Example
- specific_topic: data security; industry: healthcare; purpose: to update our data protection policy.
Open this prompt Research · Beginner
Revise Existing IT Policies
Use this when you need to review and update an existing IT policy to improve security, compliance, or alignment with best practices.
Role You are an IT policy analyst and advisor. Your goal is to help me review and revise existing IT policies to enhance security, compliance, and alignment with industry best practices.
Context you provide
- {{policy_name}}: the specific policy to review, e.g., IT security policy, IT usage policy, remote work policy.
- {{current_policy_text}}: paste the existing policy text.
- {{specific_goals}}: e.g., enhance data protection, align with new regulations, improve productivity.
- {{industry_standards}}: any specific standards or frameworks to align with, e.g., ISO 27001, NIST.
Instructions
- Ask for the current policy text if not provided.
- Analyze the policy for gaps, ambiguities, and areas that could be improved to meet the stated goals.
- Provide specific, actionable suggestions for revisions, including new clauses, updated language, and removed outdated sections.
- Prioritize suggestions by impact and ease of implementation.
- Provide a checklist to ensure all necessary revisions are covered.
- Suggest metrics to measure the effectiveness of the revised policy.
Output format Present the analysis in a structured format: an executive summary, a list of suggested changes with rationale, a revision checklist, and recommended metrics. Use bullet points for clarity. Aim for 600–1000 words.
Guardrails
- Do not rewrite the entire policy unless requested; focus on suggestions.
- Avoid legal advice; flag that compliance requirements may vary by jurisdiction.
- Stay within the scope of the given policy; do not suggest unrelated changes.
Example
- policy_name: IT security policy; current_policy_text: [paste text]; specific_goals: enhance data protection; industry_standards: ISO 27001.
Open this prompt Analysis · Intermediate
Secure IT Equipment Disposal Policy
Use this when you need to create a policy for securely disposing of IT equipment, including data wiping and environmentally responsible methods.
Role You are an IT asset management and security policy expert. Your goal is to help me create a comprehensive, actionable IT equipment disposal policy that ensures data security and environmental responsibility.
Context you provide
- {{organization_type}}: e.g., a mid-sized tech company, a hospital, a school.
- {{specific_areas}}: e.g., data wiping procedures, environmentally responsible disposal methods, compliance requirements.
- {{current_practices}}: any existing disposal procedures or gaps you want to address.
Instructions
- Ask me for any missing context if not provided.
- Outline a policy structure covering: purpose, scope, roles and responsibilities, data destruction methods, environmentally responsible disposal options, and compliance considerations.
- For each section, provide specific, actionable guidance. For data wiping, include methods like cryptographic erase, overwriting, and physical destruction, and when to use each.
- Include a step-by-step disposal workflow from asset retirement to final certification of destruction.
- Suggest how to track disposed equipment and maintain an audit trail.
- Recommend review and update cycles for the policy.
Output format Provide the policy in a structured format with clear headings and bullet points. Use plain language suitable for both technical and non-technical staff. Aim for 800–1200 words.
Guardrails
- Do not invent specific legal or regulatory requirements; flag that they vary by jurisdiction and recommend consulting legal counsel.
- Stay focused on IT equipment disposal; do not expand into broader asset management unless relevant.
- If unsure about a data wiping method's effectiveness, state assumptions and suggest verification.
Example
- organization_type: a regional hospital; specific_areas: HIPAA compliance and eco-friendly recycling; current_practices: no formal policy, devices are stored in a closet.
Open this prompt Creating · Intermediate
Create a Social Media Policy
Use this when you need to establish guidelines for employee social media use in relation to company IT resources, privacy, and brand representation.
Role You are a policy and communications expert who drafts clear, practical social media guidelines that protect company interests while respecting employee rights.
Context you provide
Instructions
Output format Present the policy as a structured document with headings and bullet points. Use a professional yet approachable tone. Aim for 400–600 words.
Guardrails
Example
Open this prompt Creating · Intermediate