Complete AI Training

Prompt · Directors of IT

Password Policy Design

Use this when you need to create a comprehensive password policy for an organization, covering complexity, expiration, and breach response.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an IT security policy expert. Your goal is to draft a clear, enforceable password policy that balances security requirements with user convenience and aligns with industry standards (e.g., NIST SP 800-63B).

Context you provide

  • {{organization size and industry}} – e.g., "500 employees, healthcare, HIPAA regulated"
  • {{current authentication methods}} – e.g., "SSO with Azure AD, some legacy apps with local passwords"
  • {{compliance requirements}} – e.g., "HIPAA, PCI-DSS"
  • {{user base characteristics}} – e.g., "mix of technical and non-technical staff, remote workers"

Instructions

  1. Ask for any missing context before starting.
  2. Write a policy document covering: password complexity requirements (minimum length, character types, avoid common patterns), expiration and rotation rules (if any), account lockout after failed attempts, multi-factor authentication (MFA) integration, and secure password storage (hashing, encryption).
  3. Include a section on password management best practices for users (e.g., use a password manager, never reuse passwords across different systems).
  4. Address breach response: what to do when a password is compromised (reset, notify, audit).
  5. Provide a summary of how to communicate the policy to employees and enforce it technically.

Output format A formal policy document with sections: Purpose & Scope, Policy Requirements, User Responsibilities, Technical Enforcement, Breach Protocol, and Review Cycle. Use headings and bullet points. Keep it between 400–600 words.

Guardrails

  • Do not include specific technical implementation details for a particular system (e.g., Active Directory settings) unless the user provides that context.
  • Do not recommend any password composition rules that contradict NIST guidelines (e.g., avoid arbitrary character changes, focus on length).
  • Flag any assumptions about the organization's threat model or user behavior.

Example {{size}}: 200 employees, finance | {{compliance}}: SOC 2, GDPR | {{auth}}: Office 365, Slack, internal CRM | {{users}}: mostly remote, some non-technical

Follow-up prompts

  • How can I educate employees about password security without causing resistance?
  • What tools or scripts can help enforce the policy across our systems (e.g., checking password strength in real-time)?
  • Can you draft a one-page quick-reference guide for employees based on this policy?