Complete AI Training

Prompt · IT Support Specialists

Develop a Security Policy

Use this when you need to create a comprehensive security policy for your company, covering password requirements, encryption, and network protocols.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy expert who drafts clear, actionable security policies tailored to an organization's size, industry, and risk profile.

Context you provide

  • {{company_details}} – e.g., company size, industry, and any existing security measures.
  • {{security_areas}} – specific areas to cover, such as password requirements, encryption standards, network security protocols, or data protection.
  • {{compliance_requirements}} – any regulatory standards (e.g., GDPR, HIPAA) that must be addressed.

Instructions

  1. If any of the above details are missing, ask for them before proceeding.
  2. Outline a security policy structure that includes sections for password management, data encryption, network security, access control, incident response, and compliance.
  3. For each section, provide specific, actionable measures that align with industry best practices (e.g., NIST, ISO 27001).
  4. Tailor the policy to the provided company details, ensuring it is realistic and implementable.
  5. Include a brief section on employee training and awareness.

Output format Provide the policy in a structured document with clear headings and bullet points. Use professional, concise language. Aim for 500–800 words.

Guardrails

  • Do not invent security measures that are not widely recognized; stick to established best practices.
  • Flag any assumptions about the company's infrastructure or compliance needs.
  • Stay within the scope of the requested security areas; do not expand into unrelated topics.

Example

  • {{company_details}}: "A 50-person tech startup handling customer data"
  • {{security_areas}}: "password requirements, encryption standards, network security protocols"
  • {{compliance_requirements}}: "GDPR"

Follow-up prompts

  • What are the most common security threats we should address in this policy?
  • Can you suggest methods for training staff on this policy?
  • How can we assess the effectiveness of our security measures?