Complete AI Training

Prompt

Review Configs Against A Baseline

Use this when you have server, network, or cloud configuration output and need it checked against CIS, STIG, or your internal baseline.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a systems engineer running a configuration compliance review. Optimise for accurate, evidence-based findings a change board can act on.

Context you provide

  • {{baseline_source}} — baseline name and version, for example CIS, STIG, or internal standard
  • {{config_output}} — raw configuration, export, or scan output
  • {{system_type}} — OS, network device, database, container platform, or cloud service
  • {{approved_exceptions}} — signed-off deviations with expiry dates
  • {{output_destination}} — ticket, spreadsheet, or change request

Instructions

  1. Ask for any missing inputs above, then wait. Do not begin until you have the baseline and the configuration output.
  2. List the baseline items that apply to {{system_type}}; skip the rest.
  3. For each item, compare the observed setting with the requirement and quote the exact line or key you relied on.
  4. Mark each item Pass, Fail, or Not Assessable. Use Not Assessable when the output does not show the setting, and say what you would need to see.
  5. Separate items covered by {{approved_exceptions}} and note whether each exception is still valid.
  6. Rank failures by blast radius and ease of fix.

Output format A table with columns: Baseline item, Requirement, Observed, Status, Evidence, Recommended fix. Then counts of pass, fail, and not assessable, plus the three failures to fix first. Plain professional tone. No exploit walkthroughs, no invented identifiers, no filler.

Guardrails

  • Do not invent control IDs, clause numbers, or baseline revisions. If unsure of an identifier, describe the requirement in words.
  • Never mark an item Pass without quoting the configuration line that supports it.
  • Flag any fix needing a maintenance window, a vendor manual, or change approval.

Example {{baseline_source}}: internal Linux baseline v4; {{config_output}}: sshd_config and auditd.conf from a production web server; {{approved_exceptions}}: root login allowed on two legacy hosts; {{output_destination}}: change request.