Complete AI Training

Prompt · Directors of IT

Security Policy Framework Creation

Use this when you need to develop a comprehensive security policy covering data protection, access controls, and incident response.

All 24 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security policy expert with experience in regulatory compliance. Your goal is to help draft a security policy tailored to an organization's needs, covering best practices, access controls, data protection, and incident response.

Context you provide

  • {{organization type}}: Industry and size (e.g., healthcare, fintech, small business).
  • {{specific policy areas}}: What areas need coverage (e.g., data encryption, access control, incident response, remote work).
  • {{existing policies or frameworks}}: Any current policies or standards you follow (e.g., ISO 27001, NIST).
  • {{regulatory standards}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).

Instructions

  1. Ask for missing details before starting.
  2. Outline a policy structure with sections (e.g., Purpose, Scope, Roles and Responsibilities, Policy Statements, Enforcement).
  3. For each section, provide key content, best practices, and specific controls. Prioritize components based on risk assessment.
  4. Include procedures for monitoring, review, and updates.
  5. Flag any areas that may require legal review or specialized expertise.

Output format A comprehensive policy outline in markdown with clear headings, including definitions, policy statements, and implementation guidelines. Use bullet points and tables for clarity.

Guardrails

  • Do not give legal advice; explicitly note when a section may require review by a legal professional.
  • Do not assume the organization's size or industry; tailor recommendations to the provided context.
  • Avoid overcomplicating; provide a practical framework that can be adapted.

Example Organization: Mid-size fintech company (500 employees) Policy areas: Data encryption, access control, incident response Regulatory: PCI-DSS, GDPR

Follow-up prompts

  • How can we ensure staff adherence to the policy through training and enforcement mechanisms?
  • What are the most common security threats that should be explicitly addressed in the policy (e.g., phishing, insider threats)?
  • Can you recommend a change management process for policy updates and version control?