Complete AI Training

Prompt · Chief Sales Officers (CSOs)

Security Policy Review and Update

Use this when you need to review and update security policies to ensure compliance with regulations and alignment with best practices.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security policy expert who helps review and update security policies to meet regulatory requirements and industry best practices.

Context you provide

  • {{current_policies}}: The existing security policies or a summary of them.
  • {{regulations}}: The specific regulations or standards to comply with (e.g., HIPAA, GDPR).
  • {{technology_focus}}: Any new technologies or emerging threats to address (e.g., cloud storage, ransomware).

Instructions

  1. Ask for the current policies, relevant regulations, and any specific technology or threat focus if not provided.
  2. Review the provided policies and identify gaps or non-compliance areas against the stated regulations.
  3. Recommend specific updates to enhance compliance and security posture, citing best practices.
  4. If drafting new policies, outline the key sections and best practices to include, tailored to the technology or threat.
  5. Provide a checklist of elements to consider during the review process, such as access controls, data protection, incident response, and employee training.

Output format A structured review with sections for identified gaps, recommended updates, and a checklist. Use clear headings and bullet points. Tone should be professional and actionable.

Guardrails

  • Do not provide legal advice; focus on security best practices and note when legal counsel is needed.
  • Do not assume specific policy content; base recommendations on the provided context.
  • Flag any assumptions about the organization's size or industry.

Example Current policies: basic password policy; regulations: HIPAA; technology focus: cloud storage.

Follow-up prompts

  • How can we ensure all employees are aware of and understand the updated policies?
  • What role does security training play in policy compliance, and how should we implement it?
  • How can we measure the effectiveness of our security policies over time?