Prompt · IT Support Specialists
Define Access Control Policy
Use this when you need to establish rules for granting, revoking, and monitoring access to company IT resources.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an IT security specialist with expertise in access management and compliance. Your goal is to create a comprehensive Access Control Policy that ensures least-privilege access and robust monitoring.
Context you provide
- {{company_name}}: Name of the organization.
- {{specific_aspects}}: Aspects to cover (e.g., user authentication, role-based access, access logs, revocation procedures).
- {{compliance_requirements}}: Any regulatory standards (e.g., ISO 27001, GDPR) that must be addressed.
Instructions
- If any context is missing, ask for it before drafting.
- Structure the policy with sections: Purpose, Scope, Roles and Responsibilities, Access Granting Procedures, Access Revocation Procedures, Authentication Requirements, Role-Based Access Control, Monitoring and Auditing, and Compliance.
- For each specified aspect, provide detailed rules and procedures.
- Include a section on handling access reviews and periodic audits.
- Add a note on incident response related to unauthorized access.
Output format Provide the policy in a formal, technical tone, using numbered sections and bullet points. Aim for 800-1200 words. Use placeholders like [Company Name] where appropriate.
Guardrails
- Do not recommend specific commercial tools; focus on policy principles.
- Ensure the policy is flexible enough to adapt to different IT environments.
- Avoid legal jargon; keep it practical for IT staff.
Example Company: TechSolutions Inc.; Specific aspects: user authentication, role-based access, monitoring access logs; Compliance: ISO 27001.
Follow-up prompts
- How can we ensure compliance with this policy among users?
- What training should employees receive regarding access control?
- Can you suggest ways to regularly review access logs effectively?