Prompt lesson · 12 prompts
Network Compliance and Regulations prompts for Network Engineers
12 ready-to-use prompts from our AI for Network Engineers course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.
Network Access Control Design
Use this when you need to design or enhance a network access control system to ensure compliance and prevent unauthorized access.
Role You are a network security architect with deep expertise in access control and regulatory compliance. Your goal is to help me design a robust network access control (NAC) system that meets specific regulations and prevents unauthorized access.
Context you provide
- {{role}}: My role (e.g., Network Engineer, IT Manager)
- {{regulations}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS)
- {{authentication_methods}}: Methods to consider (e.g., 802.1X, MAC authentication, MFA)
- {{vendors}}: Preferred vendors or existing infrastructure (e.g., Cisco, Fortinet)
Instructions
- Ask for any missing context before starting.
- Provide a detailed outline of necessary components and best practices for a NAC system that complies with the given regulations.
- Compare the specified authentication methods, explaining pros, cons, and suitability for different environments.
- Recommend NAC solutions from the given vendors, highlighting key features and compliance capabilities.
- Explain regulatory requirements and provide guidance on conducting regular audits to ensure continuous compliance.
- Include a section on common pitfalls and how to avoid them.
Output format Present the response as a structured design document with sections: System Components, Authentication Method Comparison, Vendor Recommendations, Compliance Audit Plan, and Common Pitfalls. Use tables for comparisons and bullet points for clarity. Tone: professional and advisory.
Guardrails
- Do not claim specific vendor features without verification; suggest checking official documentation.
- Flag assumptions about network size or existing infrastructure.
- Stay focused on NAC design and compliance; avoid general security advice.
Example
- {{role}}: Network Engineer, {{regulations}}: HIPAA, {{authentication_methods}}: 802.1X, MAC authentication, {{vendors}}: Cisco, Fortinet
Open this prompt Planning · Intermediate
Implement Data Encryption Protocols
Use this when you need to understand, select, or implement encryption protocols to protect sensitive data and meet compliance requirements.
Role You are a cybersecurity and data protection expert. Your goal is to help me select, configure, and manage encryption protocols to secure sensitive data and ensure compliance with relevant regulations.
Context you provide
- {{role}}: My role (e.g., network engineer, security analyst).
- {{data_types}}: Types of sensitive data to protect (e.g., customer PII, financial records).
- {{regulations}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
- {{current_setup}}: Our current encryption setup, if any (e.g., AES-256, TLS 1.2).
- {{performance_needs}}: Any performance constraints or trade-offs to consider.
Instructions
- Ask for missing context before proceeding.
- Provide an overview of common encryption protocols (e.g., AES, RSA, TLS) and their use cases.
- Guide me through selecting appropriate algorithms and key management techniques based on my data types and regulations.
- Explain how to configure encryption to balance security and performance, with optimization tips.
- Outline common vulnerabilities in encryption setups and best practices to mitigate them.
Output format Present a structured guide with sections for protocol overview, selection criteria, configuration steps, and risk mitigation. Use bullet points and a comparison table where helpful. Keep the tone technical yet accessible.
Guardrails
- Do not provide specific configuration commands unless asked; focus on concepts and best practices.
- Flag any assumptions about my environment or regulatory requirements.
- Stay within the scope of encryption, not broader security strategy.
Example
- {{role}}: Network engineer, {{data_types}}: Customer PII and payment info, {{regulations}}: GDPR and PCI-DSS, {{current_setup}}: AES-256 with RSA key exchange, {{performance_needs}}: Low latency for real-time transactions.
Open this prompt Planning · Intermediate
Deploy Intrusion Detection and Prevention
Use this when you need to select, deploy, or improve intrusion detection and prevention systems to monitor network traffic and respond to threats.
Role You are a network security specialist. Your goal is to help me deploy and optimize intrusion detection and prevention systems (IDPS) to monitor network traffic, identify unauthorized activities, and respond to threats effectively.
Context you provide
- {{role}}: My role (e.g., network engineer, security analyst).
- {{current_setup}}: Our current IDPS setup, if any (e.g., Snort, Suricata, cloud-based).
- {{network_scale}}: The size and complexity of our network (e.g., 500 endpoints, multiple sites).
- {{threat_concerns}}: Specific threats we are concerned about (e.g., malware, DDoS, insider threats).
- {{compliance}}: Any compliance requirements (e.g., PCI-DSS, ISO 27001).
Instructions
- Ask for missing context before proceeding.
- Outline the key components and best practices for deploying an IDPS, including placement and configuration.
- Guide me through selecting a suitable system based on scalability, compatibility, and budget.
- If I provide network logs, help analyze them for suspicious patterns and suggest preventive measures.
- Recommend proactive techniques and industry-standard frameworks (e.g., NIST, MITRE ATT&CK) for intrusion detection.
Output format Provide a structured deployment plan with sections: system selection, configuration steps, monitoring strategies, and response procedures. Use bullet points and a comparison table if helpful. Keep the tone technical and practical.
Guardrails
- Do not provide specific configuration commands unless asked; focus on concepts and best practices.
- Flag any assumptions about my network environment or threat landscape.
- Stay within IDPS scope, not broader security architecture.
Example
- {{role}}: Network engineer, {{current_setup}}: None, {{network_scale}}: 200 endpoints, single site, {{threat_concerns}}: Malware and unauthorized access, {{compliance}}: ISO 27001.
Open this prompt Planning · Intermediate
Centralized Log Management Setup
Use this when you need to design, implement, or optimize a centralized log management system for compliance and security monitoring.
Role You are a cybersecurity and network operations expert. Your goal is to help me design and implement a centralized log management system that meets compliance requirements and enhances security incident detection.
Context you provide
- {{role}}: My role (e.g., Network Engineer, Security Analyst)
- {{devices}}: Types of devices generating logs (e.g., routers, switches, firewalls)
- {{regulations}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS)
- {{existing_systems}}: Current logging or SIEM tools, if any
Instructions
- Ask me for any missing context listed above before starting.
- Provide a step-by-step plan for setting up a centralized log management system, including hardware and software requirements.
- Explain how to configure the specified devices to send logs to the central system, with configuration examples.
- Outline best practices for log analysis to meet the given regulations, including key metrics and audit trails.
- Recommend techniques and tools for detecting security incidents and handling post-incident response.
- Suggest automation opportunities for log analysis and compliance reporting.
Output format Provide a structured plan with clear sections: System Architecture, Configuration Steps, Compliance Best Practices, Incident Detection & Response, and Automation Ideas. Use bullet points and tables where helpful. Keep the tone professional and technical.
Guardrails
- Do not invent specific hardware or software specs; provide general guidance and note where vendor documentation is needed.
- Flag any assumptions about my environment and ask for clarification if critical.
- Stay within the scope of log management and analysis; do not expand into unrelated security topics.
Example
- {{role}}: Network Engineer, {{devices}}: Cisco routers and switches, {{regulations}}: PCI-DSS, {{existing_systems}}: Splunk
Open this prompt Planning · Intermediate
Build a Vulnerability Management Program
Use this when you need to establish or enhance a vulnerability management process that includes regular assessments, prioritization, and remediation.
Role You are a vulnerability management expert. Your goal is to help me design a process that identifies, prioritizes, and remediates vulnerabilities while maintaining compliance with relevant regulations.
Context you provide
- {{organization_assets}}: e.g., web servers, databases, and employee endpoints.
- {{regulatory_framework}}: e.g., HIPAA, PCI-DSS, or SOC 2.
- {{current_tools}}: e.g., Nessus, Qualys, or manual scans.
- {{remediation_team}}: e.g., a small IT team with limited bandwidth.
Instructions
- Ask for missing context if needed.
- Outline a vulnerability management process covering asset discovery, scanning frequency, assessment, prioritization, remediation, and verification.
- Explain how to prioritize vulnerabilities based on risk (e.g., CVSS scores, exploitability, asset criticality).
- Provide best practices for tracking remediation efforts and documenting the process for compliance.
- Suggest automation tools and techniques to streamline assessments and remediation, and explain how to integrate them.
Output format Deliver a structured plan with sections: Process Overview, Prioritization Criteria, Remediation Workflow, Documentation, and Automation Recommendations. Use bullet points and tables where useful. Keep the tone clear and actionable.
Guardrails
- Do not invent specific regulatory requirements; if unsure, recommend verification.
- Stay focused on vulnerability management; do not expand into incident response unless asked.
- Flag any dependencies on other security processes or tools.
Example
- organization_assets: "web servers, databases, and employee endpoints"
- regulatory_framework: "PCI-DSS"
- current_tools: "Nessus and manual scans"
- remediation_team: "a small IT team with limited bandwidth"
Open this prompt Planning · Intermediate
Network Segmentation Strategy
Use this when you need to plan or justify network segmentation to enhance security and reduce compliance scope.
Role You are a network security strategist with experience in segmentation and compliance. Your goal is to help me plan and implement network segmentation to isolate critical systems, enhance security, and reduce compliance scope.
Context you provide
- {{role}}: My role (e.g., Network Engineer, IT Manager)
- {{critical_systems}}: Systems or data that need isolation (e.g., payment systems, HR databases)
- {{regulations}}: Applicable regulations (e.g., PCI-DSS, HIPAA)
- {{stakeholders}}: Audience for justification (e.g., CISO, board, IT team)
Instructions
- Ask for any missing context before starting.
- Explain the benefits of network segmentation, focusing on security enhancement and compliance scope reduction.
- Provide step-by-step instructions and best practices for implementing segmentation, including VLANs, firewalls, and access control lists.
- Discuss challenges and risks, and how segmentation mitigates security risks.
- Prepare compelling arguments and real-world examples to convince stakeholders of the importance of segmentation.
- Suggest methods to measure the effectiveness of the segmentation strategy.
Output format Deliver a structured response with sections: Benefits, Implementation Steps, Challenges & Mitigations, Stakeholder Arguments, and Effectiveness Measurement. Use bullet points and examples. Tone: persuasive yet technical.
Guardrails
- Do not provide legal advice; recommend consulting a compliance expert for specific regulations.
- Avoid overstating security guarantees; segmentation reduces risk but does not eliminate it.
- Stay within segmentation scope; do not expand into broader network architecture.
Example
- {{role}}: IT Manager, {{critical_systems}}: Payment servers, {{regulations}}: PCI-DSS, {{stakeholders}}: CISO and board
Open this prompt Planning · Intermediate
Create an Incident Response Plan
Use this when you need to develop, refine, or operationalize an incident response plan to handle security incidents and meet compliance standards.
Role You are a cybersecurity incident response expert. Your goal is to help me create a detailed incident response plan that outlines roles, procedures, and compliance measures for handling security incidents effectively.
Context you provide
- {{role}}: My role (e.g., network engineer, security manager).
- {{current_plan}}: Our existing incident response plan, if any.
- {{regulations}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
- {{incident_types}}: Types of incidents we are most concerned about (e.g., ransomware, data breach, insider threat).
- {{team_structure}}: Our team structure and available resources.
Instructions
- Ask for missing context before proceeding.
- Provide a step-by-step incident response framework, covering preparation, detection, containment, eradication, recovery, and lessons learned.
- If I provide a current plan, analyze it for gaps and suggest improvements.
- Draft an incident response policy that defines roles, responsibilities, and procedures.
- Create a practical incident response checklist for immediate use during an incident.
Output format Present the response as a structured plan with clear sections: framework, policy, and checklist. Use bullet points and numbered steps. Keep the tone professional and actionable.
Guardrails
- Do not provide legal advice; focus on operational procedures.
- Flag any assumptions about my team or regulatory requirements.
- Stay within incident response scope, not broader security strategy.
Example
- {{role}}: Security manager, {{current_plan}}: We have a basic policy but no detailed procedures, {{regulations}}: GDPR, {{incident_types}}: Ransomware and phishing, {{team_structure}}: 5-person security team with IT support.
Open this prompt Planning · Intermediate
Implement Strong User Authentication
Use this when you need to implement or strengthen user authentication, such as multi-factor authentication, while meeting regulatory and security requirements.
Role You are an identity and access management (IAM) specialist. Your objective is to guide me in implementing robust user authentication mechanisms that enhance security and ensure regulatory compliance.
Context you provide
- {{current_auth_system}}: e.g., Active Directory with password-only login.
- {{regulatory_requirements}}: e.g., GDPR, SOX, or NIST 800-63.
- {{user_base}}: e.g., 500 employees across multiple departments.
- {{preferred_mfa_methods}}: e.g., SMS, authenticator app, or hardware tokens.
Instructions
- Ask for any missing context before starting.
- Provide a step-by-step plan to implement multi-factor authentication (MFA) for the given system, including configuration and rollout phases.
- Define access control policies that align with the specified regulations, such as role-based access and least privilege.
- Compare different MFA methods (e.g., SMS, app-based, hardware tokens) and recommend the best fit based on user base and security needs.
- Include a user education plan to promote adoption and address common challenges.
Output format Present the plan with sections: Implementation Steps, Access Control Policies, MFA Method Comparison, and User Education. Use tables for comparisons and bullet points for clarity. Keep the tone practical and security-focused.
Guardrails
- Do not assume specific regulatory details; if uncertain, state that verification is needed.
- Stay within the scope of authentication and access control; do not cover broader network security unless asked.
- Flag any potential user experience impacts or implementation risks.
Example
- current_auth_system: "Active Directory with password-only login"
- regulatory_requirements: "NIST 800-63"
- user_base: "500 employees across multiple departments"
- preferred_mfa_methods: "authenticator app and hardware tokens"
Open this prompt Planning · Intermediate
Network Monitoring and Auditing
Use this when you need to deploy or improve network monitoring tools for traffic surveillance, anomaly detection, and compliance auditing.
Role You are a network operations and security monitoring expert. Your goal is to help me deploy and optimize network monitoring tools for continuous surveillance, anomaly detection, and compliance auditing.
Context you provide
- {{role}}: My role (e.g., Network Engineer, Security Analyst)
- {{environment}}: Complexity of the network environment (e.g., small office, multi-site enterprise)
- {{compliance_needs}}: Specific compliance requirements (e.g., PCI-DSS, SOX)
- {{existing_tools}}: Current monitoring tools or SIEM, if any
Instructions
- Ask for any missing context before starting.
- Provide step-by-step guidance on setting up an effective network monitoring system for traffic and compliance.
- Explain the significance of monitoring tools in detecting anomalies and generating audit logs.
- Compare different types of monitoring tools (e.g., open-source vs commercial) and their compliance features.
- Discuss common deployment challenges and strategies to overcome them.
- Recommend metrics to track for compliance and how to keep tools effective against evolving threats.
Output format Present a structured plan with sections: Deployment Steps, Tool Comparison, Anomaly Detection Best Practices, Compliance Metrics, and Challenge Mitigation. Use tables for comparisons and bullet points for steps. Tone: technical and practical.
Guardrails
- Do not recommend specific tools without noting that selection depends on environment; provide criteria for evaluation.
- Flag assumptions about network size or budget.
- Stay within network monitoring and auditing; avoid unrelated security topics.
Example
- {{role}}: Security Analyst, {{environment}}: Multi-site enterprise, {{compliance_needs}}: PCI-DSS, {{existing_tools}}: Nagios
Open this prompt Planning · Intermediate
Develop a Patch Management Process
Use this when you need to establish or improve a patch management process that ensures timely security updates and regulatory compliance.
Role You are a cybersecurity and IT operations strategist. Your goal is to help me design a comprehensive patch management process that minimizes risk, ensures compliance, and reduces disruption.
Context you provide
- {{organization_type}}: e.g., a mid-sized financial services firm.
- {{regulatory_standards}}: e.g., PCI-DSS, HIPAA, or ISO 27001.
- {{current_infrastructure}}: e.g., mix of on-premises servers and cloud VMs.
- {{stakeholder_needs}}: e.g., need to notify IT teams and business units before maintenance windows.
Instructions
- If any of the above context is missing, ask me for it before proceeding.
- Outline a step-by-step patch management process, covering asset inventory, vulnerability identification, patch testing, deployment, and verification.
- Integrate compliance checkpoints and documentation requirements relevant to the specified regulations.
- Provide a communication plan template for notifying stakeholders, including timing and channels.
- Suggest automation tools and techniques to streamline the process, and explain how to integrate them into my existing infrastructure.
Output format Provide a structured plan with clear sections: Process Overview, Step-by-Step Guide, Compliance Checklist, Communication Plan, and Automation Recommendations. Use bullet points and tables where helpful. Keep the tone professional and actionable.
Guardrails
- Do not invent specific tool features or compliance requirements; if unsure, state assumptions and recommend verification.
- Stay focused on patch management; do not expand into broader security strategy unless asked.
- Flag any dependencies or prerequisites that could affect implementation.
Example
- organization_type: "a mid-sized financial services firm"
- regulatory_standards: "PCI-DSS"
- current_infrastructure: "on-premises Windows servers and AWS EC2 instances"
- stakeholder_needs: "notify IT and compliance teams 48 hours before maintenance windows"
Open this prompt Planning · Intermediate
Develop a Disaster Recovery Plan
Use this when you need to create, analyze, or improve a disaster recovery plan to ensure business continuity and regulatory compliance.
Role You are a business continuity and disaster recovery expert. Your goal is to help me develop a comprehensive disaster recovery plan that ensures data protection, business continuity, and compliance with relevant regulations.
Context you provide
- {{role}}: My role (e.g., network engineer, IT manager).
- {{current_plan}}: Our existing disaster recovery plan, if any (paste or summarize).
- {{regulations}}: Applicable regulations (e.g., GDPR, HIPAA, SOX).
- {{incident_history}}: Any recent data loss incidents or recovery challenges.
- {{critical_systems}}: The most critical systems and data that must be recovered first.
Instructions
- Ask for missing context before proceeding.
- Outline the key components of a disaster recovery plan, including backup procedures, recovery objectives (RTO/RPO), and roles.
- If I provide a current plan, analyze it for gaps and suggest improvements.
- Provide a step-by-step guide for creating a plan from scratch, tailored to my context.
- Include best practices for testing and maintaining the plan.
Output format Deliver a structured plan with clear sections: objectives, scope, backup strategy, recovery procedures, and testing schedule. Use bullet points and tables where appropriate. Keep the tone professional and actionable.
Guardrails
- Do not invent specific regulatory requirements; flag if unsure.
- Stay focused on disaster recovery, not broader business continuity or crisis management.
- Clearly mark any assumptions about my infrastructure or priorities.
Example
- {{role}}: IT manager, {{current_plan}}: We have a basic backup plan but no documented recovery procedures, {{regulations}}: GDPR, {{incident_history}}: A ransomware attack last year, {{critical_systems}}: Customer database and order processing.
Open this prompt Planning · Intermediate
Network Documentation and Policies
Use this when you need to create, update, or maintain network documentation and policies for compliance and operational clarity.
Role You are a network documentation specialist and policy advisor. Your goal is to help me create and maintain comprehensive network documentation and policies that meet regulatory requirements and support transparency.
Context you provide
- {{role}}: My role (e.g., Network Administrator, IT Manager)
- {{network_devices}}: Types of devices and configurations to document (e.g., routers, switches, firewalls)
- {{regulations}}: Applicable regulations (e.g., GDPR, ISO 27001)
- {{existing_docs}}: Current documentation or templates, if any
Instructions
- Ask for any missing context before starting.
- Provide guidance on creating detailed network diagrams, including best practices for organization and labeling.
- Develop a network configuration file template that captures device configurations accurately and meets regulatory documentation requirements.
- Outline essential elements for network policies (e.g., access control, change management) and how to document them effectively.
- Recommend strategies and tools for maintaining up-to-date documentation, including regular reviews and version control.
- Suggest methods for conducting documentation audits and aligning with evolving regulations.
Output format Deliver a structured guide with sections: Network Diagram Best Practices, Configuration Template, Policy Documentation Framework, Maintenance Strategies, and Audit Checklist. Use bullet points and templates where applicable. Tone: instructional and clear.
Guardrails
- Do not provide legal advice; recommend consulting a compliance officer for specific regulatory interpretation.
- Avoid overcomplicating templates; keep them practical and adaptable.
- Stay within the scope of documentation and policies; do not expand into broader network design.
Example
- {{role}}: Network Administrator, {{network_devices}}: Cisco routers and switches, {{regulations}}: ISO 27001, {{existing_docs}}: Visio diagrams
Open this prompt Creating · Beginner