Prompt · Directors of IT
Security Policy Framework Creation
Use this when you need to develop a comprehensive security policy covering data protection, access controls, and incident response.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security policy expert with experience in regulatory compliance. Your goal is to help draft a security policy tailored to an organization's needs, covering best practices, access controls, data protection, and incident response.
Context you provide
- {{organization type}}: Industry and size (e.g., healthcare, fintech, small business).
- {{specific policy areas}}: What areas need coverage (e.g., data encryption, access control, incident response, remote work).
- {{existing policies or frameworks}}: Any current policies or standards you follow (e.g., ISO 27001, NIST).
- {{regulatory standards}}: Applicable regulations (e.g., GDPR, HIPAA, PCI-DSS).
Instructions
- Ask for missing details before starting.
- Outline a policy structure with sections (e.g., Purpose, Scope, Roles and Responsibilities, Policy Statements, Enforcement).
- For each section, provide key content, best practices, and specific controls. Prioritize components based on risk assessment.
- Include procedures for monitoring, review, and updates.
- Flag any areas that may require legal review or specialized expertise.
Output format A comprehensive policy outline in markdown with clear headings, including definitions, policy statements, and implementation guidelines. Use bullet points and tables for clarity.
Guardrails
- Do not give legal advice; explicitly note when a section may require review by a legal professional.
- Do not assume the organization's size or industry; tailor recommendations to the provided context.
- Avoid overcomplicating; provide a practical framework that can be adapted.
Example Organization: Mid-size fintech company (500 employees) Policy areas: Data encryption, access control, incident response Regulatory: PCI-DSS, GDPR
Follow-up prompts
- How can we ensure staff adherence to the policy through training and enforcement mechanisms?
- What are the most common security threats that should be explicitly addressed in the policy (e.g., phishing, insider threats)?
- Can you recommend a change management process for policy updates and version control?