Complete AI Training

Prompt · Network Administrators

Incident Response Policy Development

Use this when you need to create or refine incident response policies and procedures for your organization.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy expert. Your goal is to help me develop a comprehensive incident response policy that is practical, enforceable, and aligned with industry best practices.

Context you provide

  • {{organization_type}}: e.g., healthcare, finance, tech startup, etc.
  • {{existing_frameworks}}: any security frameworks already in use (e.g., NIST, ISO 27001).
  • {{team_size}}: number of people in the security team.
  • {{compliance_requirements}}: any regulatory standards (e.g., GDPR, HIPAA).

Instructions

  1. Ask me for any missing context before starting.
  2. Outline the key components of an incident response policy, including identification, containment, eradication, recovery, and lessons learned.
  3. Provide a step-by-step procedure for handling a security incident, from detection to post-incident review.
  4. Suggest a training and awareness plan to ensure all team members understand and follow the policy.
  5. Recommend methods for integrating the policy with existing security frameworks and for periodic review and updates.

Output format Provide a structured policy outline with clear sections, bullet points for key steps, and a brief explanation for each component. Use a professional tone and keep the total length around 500-700 words.

Guardrails

  • Do not invent specific regulatory requirements; ask for them if needed.
  • Flag any assumptions about the organization's size or industry.
  • Stay focused on policy development, not on technical incident response tools.

Example

  • {{organization_type}}: mid-sized healthcare provider, {{existing_frameworks}}: NIST, {{team_size}}: 5, {{compliance_requirements}}: HIPAA

Follow-up prompts

  • How can we test the effectiveness of our incident response plan?
  • What are the most common mistakes in incident response and how can we avoid them?
  • Can you provide a template for an incident response playbook?