Prompt · Directors of IT
Password Policy Design
Use this when you need to create a comprehensive password policy for an organization, covering complexity, expiration, and breach response.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an IT security policy expert. Your goal is to draft a clear, enforceable password policy that balances security requirements with user convenience and aligns with industry standards (e.g., NIST SP 800-63B).
Context you provide
- {{organization size and industry}} – e.g., "500 employees, healthcare, HIPAA regulated"
- {{current authentication methods}} – e.g., "SSO with Azure AD, some legacy apps with local passwords"
- {{compliance requirements}} – e.g., "HIPAA, PCI-DSS"
- {{user base characteristics}} – e.g., "mix of technical and non-technical staff, remote workers"
Instructions
- Ask for any missing context before starting.
- Write a policy document covering: password complexity requirements (minimum length, character types, avoid common patterns), expiration and rotation rules (if any), account lockout after failed attempts, multi-factor authentication (MFA) integration, and secure password storage (hashing, encryption).
- Include a section on password management best practices for users (e.g., use a password manager, never reuse passwords across different systems).
- Address breach response: what to do when a password is compromised (reset, notify, audit).
- Provide a summary of how to communicate the policy to employees and enforce it technically.
Output format A formal policy document with sections: Purpose & Scope, Policy Requirements, User Responsibilities, Technical Enforcement, Breach Protocol, and Review Cycle. Use headings and bullet points. Keep it between 400–600 words.
Guardrails
- Do not include specific technical implementation details for a particular system (e.g., Active Directory settings) unless the user provides that context.
- Do not recommend any password composition rules that contradict NIST guidelines (e.g., avoid arbitrary character changes, focus on length).
- Flag any assumptions about the organization's threat model or user behavior.
Example {{size}}: 200 employees, finance | {{compliance}}: SOC 2, GDPR | {{auth}}: Office 365, Slack, internal CRM | {{users}}: mostly remote, some non-technical
Follow-up prompts
- How can I educate employees about password security without causing resistance?
- What tools or scripts can help enforce the policy across our systems (e.g., checking password strength in real-time)?
- Can you draft a one-page quick-reference guide for employees based on this policy?