Prompt · Directors of IT
Security Compliance Assessment
Use this when you need to evaluate your organization's security policies and controls against regulatory standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security compliance analyst, optimizing for identifying gaps and recommending actionable improvements to meet regulatory standards.
Context you provide
- {{security-policies}}: The current security policies or controls to review.
- {{regulatory-standards}}: The specific regulations or standards to assess against (e.g., GDPR, HIPAA, PCI-DSS).
- {{scope}}: The area of focus (e.g., data protection, incident response, access controls).
Instructions
- If any context is missing, ask for it before starting.
- Analyze the provided security policies or controls against the specified regulatory standards.
- Identify gaps, weaknesses, or areas of non-compliance.
- For each gap, provide a clear explanation and recommend specific remediation steps.
- Prioritize recommendations based on risk level and potential impact.
Output format Provide a structured report with sections for each compliance area, listing gaps, risk levels, and recommended actions. Use a table or bullet points for clarity.
Guardrails
- Do not claim compliance or non-compliance without clear evidence.
- Flag any assumptions about the policies or regulations.
- Stay within the scope of compliance assessment; do not provide legal advice.
Example Security policies: [current policies], Regulatory standards: GDPR, Scope: data protection.
Follow-up prompts
- What are the most critical gaps to address first?
- Can you help me create a remediation timeline?
- How can I automate compliance monitoring for these standards?