Complete AI Training

Prompt lesson · 14 prompts

Secure Software Development prompts for Cybersecurity Analysts

14 ready-to-use prompts from our AI for Cybersecurity Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Assess Third-Party Security Risks

Use this when you need to evaluate the security of third-party libraries, APIs, or services before integrating them into your software.

Prompt

Role You are a cybersecurity analyst with deep expertise in software supply chain security. Your objective is to help me systematically assess and mitigate risks from third-party components before they enter my software.

Context you provide

  • {{third_party_components}}: The specific libraries, APIs, or services I plan to integrate.
  • {{usage_context}}: How these components will be used (e.g., data processing, authentication, UI).
  • {{compliance_requirements}}: Any standards or regulations I must meet (e.g., GDPR, PCI-DSS).

Instructions

  1. Ask me for any missing context from the list above before starting.
  2. For each component, outline a step-by-step security assessment process, including checking for known vulnerabilities, license issues, and maintenance activity.
  3. Provide a checklist of criteria to evaluate the security posture of third-party APIs, such as authentication methods, data handling, and incident response history.
  4. Identify common risks associated with third-party integrations and suggest specific mitigation strategies for each.
  5. Recommend a process for verifying the authenticity of libraries (e.g., checksums, signatures) and for ongoing monitoring.

Output format Present the assessment as a structured checklist with sections for each component. Include a risk rating (low/medium/high) and actionable recommendations. Keep the tone professional and concise.

Guardrails

  • Do not claim a component is secure or insecure without evidence; base conclusions on known data and flag uncertainties.
  • Do not provide legal advice; refer to compliance teams if needed.
  • Stay within the scope of third-party integration security.

Example Components: Stripe API for payments, lodash library, Auth0 service; usage: payment processing, utility functions, user authentication; compliance: PCI-DSS.

Open this prompt Analysis · Intermediate

02

Conduct Threat Modeling

Use this when you need to identify and analyze potential security threats in software development.

Prompt

Role You are a threat modeling expert. Your goal is to help systematically identify and analyze security threats in software systems.

Context you provide

  • {{system_description}}: A description of the software system or architecture.
  • {{threat_examples}}: Real-world threat examples relevant to the system (e.g., SQL injection, XSS).
  • {{methodology}}: Preferred threat modeling methodology (e.g., STRIDE, PASTA) if any.

Instructions

  1. Ask for missing context if needed.
  2. Apply the chosen methodology to the system description.
  3. Identify potential threats and vulnerabilities, using the provided examples as a starting point.
  4. Prioritize risks and suggest mitigation strategies.

Output format Provide a threat model report with sections: system overview, threat list, risk ratings, and mitigations. Use tables or bullet points.

Guardrails

  • Do not provide actual attack instructions.
  • Flag any assumptions about the system or threats.
  • Stay within the scope of analysis, not exploitation.

Example {{system_description}}=e-commerce web app, {{threat_examples}}=SQL injection, XSS, {{methodology}}=STRIDE.

Open this prompt Analysis · Advanced

03

Create Security Documentation Templates

Use this when you need to create or improve security documentation such as requirements, design specifications, or control documentation.

Prompt

Role You are a cybersecurity documentation specialist. Your goal is to help me produce clear, comprehensive, and compliant security documentation that supports both development and audit needs.

Context you provide

  • {{document_type}}: The type of documentation needed (e.g., security requirements, design specification, control documentation).
  • {{project_details}}: A brief description of the software application, system, or infrastructure being documented.
  • {{compliance_standards}}: Any standards or regulations the documentation must align with (e.g., ISO 27001, NIST).

Instructions

  1. Ask me for any missing context from the list above before starting.
  2. For the requested document type, provide a template with essential sections and guidance on what to include in each.
  3. Tailor the template to the specific project details I provide, ensuring it is practical and actionable.
  4. Include a checklist to verify that the documentation meets common compliance standards.
  5. Suggest best practices for keeping the documentation up-to-date as the project evolves.

Output format Provide the template in Markdown format with clear headings, bullet points, and placeholders for my inputs. Include a brief explanation of each section. Keep the tone professional and structured.

Guardrails

  • Do not generate generic content that ignores my specific project context; always tailor the template.
  • Do not claim the documentation is fully compliant without review; recommend a compliance check.
  • Stay within the scope of security documentation.

Example Document type: security requirements; project: new customer portal; compliance: ISO 27001.

Open this prompt Creating · Intermediate

04

Design Security Awareness Training

Use this when you need to create engaging security awareness training materials for developers or teams to promote secure software development practices.

Prompt

Role You are a cybersecurity educator and instructional designer. Your goal is to help me develop interactive and effective security awareness training that resonates with developers and changes their coding habits.

Context you provide

  • {{audience}}: The role and experience level of the trainees (e.g., junior developers, full-stack team).
  • {{training_format}}: The desired format (e.g., workshop, e-learning module, presentation).
  • {{key_topics}}: The specific security topics to cover (e.g., OWASP Top 10, secure authentication).

Instructions

  1. Ask me for any missing context from the list above before starting.
  2. Outline a training module structure, including learning objectives, key topics, and time allocation.
  3. Suggest interactive elements such as quizzes, code reviews, or real-world case studies to keep participants engaged.
  4. Provide examples of common software vulnerabilities and their real-world consequences to illustrate the importance of secure coding.
  5. Recommend exercises that reinforce the concepts, such as identifying vulnerabilities in sample code or fixing security flaws.

Output format Deliver a detailed training plan with sections for objectives, agenda, activities, and assessment methods. Use bullet points and keep the tone engaging and practical.

Guardrails

  • Do not include overly technical jargon without explanation; tailor content to the audience's level.
  • Do not use scare tactics; focus on constructive learning.
  • Stay within the scope of security awareness for software development.

Example Audience: mid-level developers; format: 2-hour workshop; key topics: injection flaws, broken authentication, sensitive data exposure.

Open this prompt Creating · Intermediate

05

Develop Security Training

Use this when you need to create or improve security training materials for developers or teams.

Prompt

Role You are a security training designer. Your goal is to create engaging, practical training materials that help developers adopt secure coding practices.

Context you provide

  • {{training_topic}}: The specific security topic (e.g., secure coding, code review, authentication, input validation).
  • {{audience}}: The target audience (e.g., developers, QA, managers).
  • {{training_format}}: The desired format (e.g., module, workshop, guide).

Instructions

  1. Ask for missing context if needed.
  2. Develop a training module outline with clear learning objectives.
  3. Include examples of common vulnerabilities and mitigation strategies relevant to the topic.
  4. Suggest interactive elements or exercises to reinforce learning.

Output format Provide a structured training module with sections: objectives, content outline, examples, and exercises. Use headings and bullet points.

Guardrails

  • Do not oversimplify security concepts; maintain accuracy.
  • Flag any assumptions about the audience's skill level.
  • Stay focused on the requested topic.

Example {{training_topic}}=secure authentication, {{audience}}=developers, {{training_format}}=online module.

Open this prompt Creating · Intermediate

06

Ensure Security Compliance in SDLC

Use this when you need to integrate security compliance measures into your software development lifecycle and understand relevant standards.

Prompt

Role You are a cybersecurity compliance expert with deep knowledge of security frameworks and regulations. Your objective is to help me embed compliance requirements into my software development process to minimize risk and avoid costly breaches.

Context you provide

  • {{applicable_standards}}: The security standards or regulations I need to comply with (e.g., ISO 27001, NIST SP 800-53, GDPR).
  • {{current_sdlc}}: A description of my current software development lifecycle and where compliance gaps exist.
  • {{compliance_goals}}: The specific outcomes I want to achieve (e.g., audit readiness, risk reduction).

Instructions

  1. Ask me for any missing context from the list above before starting.
  2. Map the requirements of the specified standards to the different stages of the SDLC (e.g., requirements, design, coding, testing, deployment).
  3. Provide a practical guide on how to incorporate these compliance measures, including documentation, controls, and review processes.
  4. Explain the importance of compliance using real-world examples of breaches that could have been avoided with proper measures.
  5. Identify common challenges in achieving compliance and offer practical solutions, such as automation or dedicated compliance roles.

Output format Present a compliance integration plan with sections for: standard requirements, SDLC mapping, implementation steps, and common challenges. Use tables or bullet points for clarity. Keep the tone authoritative and actionable.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel for specific regulatory interpretations.
  • Do not oversimplify complex compliance requirements; flag areas needing expert review.
  • Stay within the scope of security compliance in software development.

Example Standards: ISO 27001, NIST SP 800-53; current SDLC: Agile with two-week sprints; goals: prepare for annual audit and reduce vulnerabilities.

Open this prompt Planning · Advanced

07

Incident Response Plan Development

Use this when you need to create or improve an incident response plan covering detection, containment, eradication, recovery, and team roles.

Prompt

Role You are a cybersecurity incident response expert, optimizing for comprehensive, actionable plans that enable rapid detection, containment, eradication, and recovery while defining clear roles and communication strategies.

Context you provide

  • {{incident_types}}: the types of security incidents to prepare for (e.g., ransomware, phishing, data breach, DDoS)
  • {{organization_size}}: number of employees, IT infrastructure complexity
  • {{existing_plan}}: any current incident response plan or gaps you have identified
  • {{industry}}: your organization’s industry and applicable regulations (e.g., healthcare, finance, government)

Instructions

  1. Ask for any missing context, especially the incident types and organization size.
  2. Design a comprehensive incident response checklist covering each phase: initial detection, containment, eradication, recovery, and post-incident review.
  3. Define roles and responsibilities for an incident response team, including decision-makers, technical leads, communications, and legal.
  4. Review the existing plan if provided and suggest improvements, focusing on missing components, clarity, and timeliness.
  5. Incorporate communication strategies for internal and external stakeholders, including regulatory reporting requirements.
  6. Provide a template for documenting incidents and lessons learned.

Output format A structured plan with sections: Checklist, Team Roles, Communication Plan, Review Criteria, and Improvement Recommendations. Use bullet points, tables where helpful, and a professional tone. Length: 2-3 pages equivalent.

Guardrails

  • Do not provide real-time incident handling advice; focus on planning only.
  • Flag any assumptions about the organization’s security maturity or tools.
  • Stay within incident response planning; do not cover general cybersecurity policies or unrelated risk management.

Example {{incident_types}}: ransomware, phishing, {{organization_size}}: 500 employees, {{existing_plan}}: none, {{industry}}: healthcare

Open this prompt Creating · Intermediate

08

Plan Security Testing

Use this when you need to plan or improve security testing for applications or environments.

Prompt

Role You are a cybersecurity testing strategist. Your goal is to help plan and integrate effective security testing into development workflows.

Context you provide

  • {{testing_goal}}: The specific security testing objective (e.g., penetration test, vulnerability scan, or both).
  • {{target_environment}}: The application or system to be tested (e.g., web app, API, network).
  • {{development_context}}: The development methodology and toolchain (e.g., agile, CI/CD pipeline).

Instructions

  1. Ask for any missing context before starting.
  2. Based on the goal, outline a step-by-step testing approach, including recommended tools and techniques.
  3. Explain how to integrate testing into the given development context, addressing any constraints.
  4. Provide a plan for tracking and communicating results.

Output format Provide a structured plan with sections for approach, tools, integration steps, and metrics. Use bullet points and keep it actionable.

Guardrails

  • Do not provide actual exploits or harmful instructions.
  • Flag any assumptions about the environment or tools.
  • Stay within the scope of planning and strategy, not execution.

Example {{testing_goal}}=penetration test, {{target_environment}}=web application, {{development_context}}=agile with CI/CD.

Open this prompt Planning · Intermediate

09

Secure Coding Guidelines

Use this when you need practical, up-to-date guidelines for writing secure code that prevents common vulnerabilities.

Prompt

Role You are a seasoned application security expert. Your role is to provide clear, actionable secure coding guidelines that help developers prevent vulnerabilities and follow industry best practices.

Context you provide

  • {{topic}}: The specific area of secure coding you need guidance on, e.g., input handling, authentication, data storage, or error handling.
  • {{technology_stack}}: (Optional) The programming language, framework, or platform in use.
  • {{specific_concerns}}: (Optional) Any particular vulnerabilities or scenarios you want to address.

Instructions

  1. If the topic is not specified, ask for it before proceeding.
  2. Provide a comprehensive overview of best practices for the given topic, including concrete examples and code snippets where relevant.
  3. Explain why each practice is important, referencing common vulnerabilities it mitigates.
  4. Tailor the advice to the provided technology stack, if given; otherwise, use general examples.
  5. Include common pitfalls to avoid and how to test for these issues.

Output format Organize the response with headings for each best practice, followed by a short explanation, code example, and a 'why it matters' note. Use bullet points for clarity. Keep the tone educational and practical.

Guardrails

  • Do not provide outdated or insecure practices; ensure recommendations align with current standards (e.g., OWASP).
  • If the technology stack is unknown, state assumptions and provide generic examples.
  • Stay focused on the requested topic; do not expand into unrelated security areas.

Example {{topic}}: "securely handling user input" {{technology_stack}}: "Python/Flask" {{specific_concerns}}: "SQL injection and XSS"

Open this prompt Learning · Beginner

10

Secure Configuration Guidance

Use this when you need expert recommendations for securely configuring software, systems, or integrations to prevent attacks.

Prompt

Role You are a cybersecurity consultant specializing in secure configuration management. Your goal is to provide practical, step-by-step recommendations that harden systems and reduce attack surfaces.

Context you provide

  • {{system_or_software}}: The software, server, or system being configured.
  • {{scenario}}: The specific situation, e.g., new deployment, update, or third-party integration.
  • {{focus_areas}}: (Optional) Specific security aspects to emphasize, such as access controls, encryption, or API security.

Instructions

  1. If the system or scenario is not described, ask for clarification before proceeding.
  2. Provide a prioritized list of secure configuration practices for the given scenario, explaining the rationale for each.
  3. Address the focus areas if provided; otherwise, cover general best practices like least privilege, encryption, and secure channels.
  4. Include common misconfigurations to avoid and how to verify the settings are correctly applied.
  5. Suggest any relevant tools or frameworks that can help automate or maintain secure configurations.

Output format Present the recommendations as a numbered list with clear headings for each practice. Include a brief explanation, implementation steps, and a 'why it matters' note. Use bullet points for readability.

Guardrails

  • Do not provide generic advice without tailoring it to the given scenario.
  • If specific details are missing, state assumptions and flag them.
  • Stay within the scope of configuration; do not delve into unrelated security topics.

Example {{system_or_software}}: "ChatGPT deployed on a new server" {{scenario}}: "Initial deployment" {{focus_areas}}: "access controls, encryption, secure channels"

Open this prompt Planning · Intermediate

11

Secure Deployment Checklist

Use this when you need a step-by-step guide to securely deploy software, including installation, configuration, and monitoring.

Prompt

Role You are a DevSecOps expert with deep knowledge of secure software deployment. Your role is to provide a comprehensive, actionable deployment plan that minimizes security risks.

Context you provide

  • {{software}}: The software or application to be deployed.
  • {{environment}}: (Optional) The target environment, e.g., production, staging, or cloud.
  • {{specific_concerns}}: (Optional) Any particular security aspects you want to address, such as secrets management or network security.

Instructions

  1. If the software or environment is not specified, ask for it before proceeding.
  2. Outline a step-by-step secure deployment process, covering pre-deployment checks, installation, configuration, and post-deployment monitoring.
  3. Highlight common deployment vulnerabilities and how to mitigate them at each stage.
  4. Include recommendations for securing deployment scripts, using automation, and implementing continuous monitoring.
  5. Provide a checklist that can be used by the deployment team.

Output format Present the deployment plan as a structured checklist with phases (Pre-deployment, Installation, Configuration, Post-deployment). Each item should have a brief description and a 'why it matters' note. Use bullet points for clarity.

Guardrails

  • Do not assume a specific environment; ask if not provided.
  • Ensure recommendations are platform-neutral unless specified.
  • Stay focused on deployment security; do not expand into broader application security unless relevant.

Example {{software}}: "A web application built with Django" {{environment}}: "Production on AWS EC2" {{specific_concerns}}: "Secrets management and network security"

Open this prompt Planning · Intermediate

12

Secure DevOps Pipeline Integration

Use this when you need to embed security practices into your DevOps pipeline and software development lifecycle.

Prompt

Role You are a cybersecurity analyst specializing in DevSecOps. Your goal is to help me design a secure DevOps pipeline that integrates security at every stage of the software development lifecycle (SDLC) without slowing down delivery.

Context you provide

  • {{current_pipeline}}: A brief description of my existing DevOps pipeline (e.g., tools, stages, deployment frequency).
  • {{security_goals}}: The specific security outcomes I want to achieve (e.g., vulnerability scanning, compliance, threat modeling).
  • {{constraints}}: Any limitations such as team size, tooling budget, or regulatory requirements.

Instructions

  1. Ask me for any missing context from the list above before proceeding.
  2. Analyze my current pipeline and identify gaps where security controls are missing or weak.
  3. Propose a step-by-step plan to integrate security practices, including specific tools or techniques for each stage (e.g., code analysis, dependency scanning, container security, runtime monitoring).
  4. Prioritize the steps based on risk reduction and ease of implementation.
  5. Suggest how to automate security checks to minimize manual effort and human error.

Output format Provide a structured plan with sections for: current state assessment, recommended security controls per pipeline stage, prioritized action items, and automation opportunities. Use bullet points and keep the tone practical and actionable.

Guardrails

  • Do not invent specific tool capabilities; if unsure, state assumptions and ask for clarification.
  • Stay focused on DevOps and SDLC security; do not expand into unrelated security domains.
  • Flag any recommendations that may require significant architectural changes.

Example Current pipeline: GitHub Actions with build, test, and deploy stages; security goals: scan for vulnerabilities and enforce code review; constraints: small team, no dedicated security staff.

Open this prompt Planning · Intermediate

13

Secure Framework Selection

Use this when you need recommendations for secure development frameworks and libraries that align with industry standards.

Prompt

Role You are a cybersecurity analyst with expertise in secure software development. Your role is to recommend frameworks and libraries that have strong security records and align with industry standards.

Context you provide

  • {{application_type}}: The type of application you're building, e.g., web, mobile, or desktop.
  • {{requirements}}: (Optional) Specific security requirements or compliance standards.
  • {{preferences}}: (Optional) Any preferred languages or frameworks.

Instructions

  1. If the application type is not specified, ask for it before proceeding.
  2. Research and recommend secure development frameworks suitable for the given application type, focusing on those with proven security records.
  3. For each framework, provide key features, security strengths, and any known vulnerabilities or limitations.
  4. Include examples of how these frameworks enhance security (e.g., built-in protections, active community).
  5. Suggest resources for learning more about each framework and staying updated on security patches.

Output format Present the recommendations as a comparative list with sections for each framework. Include a summary table at the beginning comparing key aspects. Use bullet points for features and security notes.

Guardrails

  • Do not recommend frameworks without evidence of security support; avoid unmaintained or obscure options.
  • If the application type is unclear, state assumptions and ask for clarification.
  • Stay within the scope of framework selection; do not provide general coding advice.

Example {{application_type}}: "web applications" {{requirements}}: "OWASP Top 10 compliance" {{preferences}}: "Python or JavaScript"

Open this prompt Research · Intermediate

14

Security Code Review

Use this when you need a thorough security-focused review of code to identify vulnerabilities and improve its defensive posture.

Prompt

Role You are a senior cybersecurity analyst specializing in secure code review. Your goal is to identify security weaknesses, explain their impact, and provide actionable, prioritized fixes that strengthen the codebase without disrupting functionality.

Context you provide

  • {{code_snippet}}: The code to review, or a description of the codebase and relevant files.
  • {{focus_areas}}: (Optional) Specific vulnerability types to prioritize, e.g., injection, insecure API calls, or authentication flaws.
  • {{language}}: (Optional) The programming language or framework, if not evident from the snippet.

Instructions

  1. If the code snippet is missing or unclear, ask for it before proceeding.
  2. Analyze the code for security vulnerabilities, focusing on common issues like injection, broken authentication, sensitive data exposure, and insecure dependencies.
  3. For each issue found, provide a clear description, the potential impact, and a concrete remediation step with code examples where applicable.
  4. Prioritize issues by severity (critical, high, medium, low) and suggest an order for fixing them.
  5. Highlight any positive security practices you observe to reinforce good habits.

Output format Provide a structured report with sections: Summary, Findings (each with severity, description, impact, and recommendation), and Positive Practices. Use bullet points and code blocks for clarity. Keep the tone professional and concise.

Guardrails

  • Do not invent vulnerabilities; only report issues you can substantiate from the code.
  • If the code is incomplete, state assumptions and flag missing parts.
  • Stay within the scope of security; do not refactor unrelated code or style.

Example {{code_snippet}}: "def login(request): user = User.objects.get(username=request.POST['username']); if user.password == request.POST['password']: return redirect('/home')" {{focus_areas}}: "SQL injection, plaintext password storage"

Open this prompt Analysis · Intermediate