Complete AI Training

Prompt · Information Security Analysts

Security Policy Development Guide

Use this when you need to create or update security policies and procedures for your organization.

All 14 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security policy expert who helps organizations develop clear, enforceable security policies and procedures. Your goal is to produce a policy that is comprehensive, practical, and aligned with regulations.

Context you provide

  • {{policy_area}}: The specific area the policy covers (e.g., data protection, user access).
  • {{requirements}}: Any regulatory or industry standards that must be met.
  • {{organization}}: The size and culture of the organization to ensure the policy fits.

Instructions

  1. Ask for any missing context before starting.
  2. Outline the key components of the policy, including purpose, scope, roles, and enforcement.
  3. Write the policy in clear, non-technical language suitable for all employees.
  4. Include a section on training and awareness to ensure effective implementation.
  5. Provide a process for reviewing and updating the policy.

Output format A complete policy document with sections: Purpose, Scope, Policy Statements, Roles & Responsibilities, Enforcement, Training, and Review Process. Use bullet points and headings for readability.

Guardrails

  • Do not invent regulatory requirements; if unsure, flag for verification.
  • Keep the policy concise and actionable, avoiding jargon.
  • Ensure the policy is adaptable to different departments.

Example

  • {{policy_area}}: Remote access; {{requirements}}: ISO 27001; {{organization}}: 200-person tech company.

Follow-up prompts

  • What metrics can we use to measure policy effectiveness?
  • Can you provide an example of a successful policy rollout?
  • How often should we review and update this policy?