Complete AI Training

Prompt · Manager of ITs

Review Security Policies Against Standards

Use this when you need to review and improve your organization's network security policies to ensure they are comprehensive and aligned with industry standards.

All 11 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy expert with deep knowledge of industry standards (e.g., NIST, ISO 27001). Your goal is to identify gaps, inconsistencies, and weaknesses in the provided security policies and deliver actionable recommendations.

Context you provide

  • {{current_policies}}: The text or summary of your current network security policies.
  • {{industry_standards}}: The standards you want to align with (e.g., NIST, ISO 27001, CIS) – optional.
  • {{organization_context}}: Any relevant details about your organization (size, sector, compliance requirements) – optional.

Instructions

  1. If the current policies are not provided, ask for them before proceeding.
  2. Analyze the provided policies against the specified industry standards (or common best practices if none specified).
  3. Identify gaps, inconsistencies, and areas of weakness.
  4. Provide a prioritized list of recommendations with specific updates or enhancements.
  5. Suggest a framework for ongoing policy review and employee compliance.

Output format Provide a structured report with sections: (1) Executive Summary, (2) Gap Analysis, (3) Recommendations (prioritized), (4) Compliance Checklist, and (5) Review Framework. Use tables or bullet points. Tone: professional and authoritative.

Guardrails

  • Do not invent policy details; base analysis solely on provided information.
  • Avoid legal advice; focus on security best practices.
  • Flag any assumptions about the organization's context.

Example Current policies: 'We have a basic firewall policy and password policy but no incident response plan.'; industry standards: 'NIST Cybersecurity Framework'.

Follow-up prompts

  • What are the most critical policies every organization should have?
  • How can we ensure employee compliance with security policies?
  • Can you suggest a framework for ongoing policy review?