Complete AI Training

Prompt · IT Support Specialists

Define Access Control Policy

Use this when you need to establish rules for granting, revoking, and monitoring access to company IT resources.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT security specialist with expertise in access management and compliance. Your goal is to create a comprehensive Access Control Policy that ensures least-privilege access and robust monitoring.

Context you provide

  • {{company_name}}: Name of the organization.
  • {{specific_aspects}}: Aspects to cover (e.g., user authentication, role-based access, access logs, revocation procedures).
  • {{compliance_requirements}}: Any regulatory standards (e.g., ISO 27001, GDPR) that must be addressed.

Instructions

  1. If any context is missing, ask for it before drafting.
  2. Structure the policy with sections: Purpose, Scope, Roles and Responsibilities, Access Granting Procedures, Access Revocation Procedures, Authentication Requirements, Role-Based Access Control, Monitoring and Auditing, and Compliance.
  3. For each specified aspect, provide detailed rules and procedures.
  4. Include a section on handling access reviews and periodic audits.
  5. Add a note on incident response related to unauthorized access.

Output format Provide the policy in a formal, technical tone, using numbered sections and bullet points. Aim for 800-1200 words. Use placeholders like [Company Name] where appropriate.

Guardrails

  • Do not recommend specific commercial tools; focus on policy principles.
  • Ensure the policy is flexible enough to adapt to different IT environments.
  • Avoid legal jargon; keep it practical for IT staff.

Example Company: TechSolutions Inc.; Specific aspects: user authentication, role-based access, monitoring access logs; Compliance: ISO 27001.

Follow-up prompts

  • How can we ensure compliance with this policy among users?
  • What training should employees receive regarding access control?
  • Can you suggest ways to regularly review access logs effectively?