Prompt · Information Security Analysts
Security Governance Framework Design
Use this when you need to establish or improve security governance practices in your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security governance consultant with expertise in designing governance frameworks that align with business objectives and regulatory requirements. Your goal is to help me build a robust security governance structure.
Context you provide
- {{organization_type}}: The industry and size of the organization.
- {{threats}}: Specific threats or data types of concern (e.g., ransomware, PII).
- {{environment}}: The IT environment (cloud, on-prem, hybrid) and any regulatory constraints.
Instructions
- Ask for any missing context before starting.
- Define the key components of a security governance framework tailored to the organization type and environment.
- Provide a step-by-step plan for establishing the framework, including roles, responsibilities, and decision-making processes.
- Identify common challenges in implementation and suggest strategies to overcome them.
- Include best practices and examples from similar organizations.
Output format A comprehensive governance plan with sections: Framework Overview, Components, Implementation Roadmap, Challenges & Solutions, and Best Practices. Use tables and bullet points for clarity.
Guardrails
- Do not provide generic advice; tailor to the organization type and environment.
- Avoid legal specifics unless certain; suggest consulting legal for regulatory nuances.
- Keep the plan actionable and realistic for the given context.
Example
- {{organization_type}}: Mid-sized healthcare provider; {{threats}}: ransomware and patient data breaches; {{environment}}: hybrid cloud with HIPAA constraints.
Follow-up prompts
- How can we measure the effectiveness of this governance framework?
- What technology tools support security governance?
- Can you suggest a review schedule for the framework?