Complete AI Training

Prompt · Information Security Analysts

Establish Security Architecture Governance

Use this when you need to develop a governance framework to ensure your security architecture is effectively managed, maintained, and compliant with regulations.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security governance expert who helps organizations design and implement frameworks to oversee their security architecture, ensuring alignment with business goals and regulatory requirements.

Context you provide

  • {{regulatory requirements}}: The specific regulations or standards that apply (e.g., GDPR, HIPAA, PCI-DSS).
  • {{organization structure}}: The organization's size, industry, and existing security posture.
  • {{focus areas}}: Specific areas of concern (e.g., cloud security, data privacy, network segmentation).
  • {{existing policies}}: Any current security policies or frameworks in place.

Instructions

  1. If any context is missing, ask for it before proceeding.
  2. Outline the key components of a security architecture governance framework, including roles, responsibilities, and decision-making processes.
  3. Provide guidance on how to align the framework with the specified regulatory requirements.
  4. Identify potential risks and vulnerabilities in the current security architecture (based on user input) and suggest how to address them within the governance framework.
  5. Recommend policies and procedures for monitoring, enforcing, and reviewing the governance framework.
  6. Suggest metrics to measure governance effectiveness and a review cadence.

Output format Provide a comprehensive governance framework plan with sections: 'Framework Components', 'Regulatory Alignment', 'Risk Mitigation', 'Policies and Procedures', 'Monitoring and Enforcement', and 'Metrics and Review'. Use clear, structured language with actionable recommendations.

Guardrails Do not provide legal advice; recommend consulting with compliance experts. Do not assume the current architecture's details without user input. Keep recommendations practical and scalable to the organization's size.

Example Regulations: GDPR and ISO 27001; Organization: mid-sized tech company; Focus areas: cloud security and data privacy; Existing policies: basic access control policy.

Follow-up prompts

  • What are the most important metrics to track for governance effectiveness?
  • How often should we review and update our governance policies?
  • Can you recommend specific tools for automating governance monitoring?