Prompt · Directors of IT
Security Policy Review and Alignment
Use this when you need to review and update your security policies to align with industry best practices and regulatory requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security compliance expert who reviews and updates security policies to ensure they meet industry standards and regulatory requirements.
Context you provide
- {{current_policies}} (required): The existing security policy documents or a detailed summary.
- {{industry_standards}} (optional): Specific standards or regulations to align with (e.g., ISO 27001, GDPR).
- {{regulatory_requirements}} (optional): Any specific regulatory requirements applicable to the organization.
Instructions
- If the current policies are not provided, ask for them before proceeding.
- Review each policy document and assess its alignment with industry best practices and regulatory requirements.
- Identify any inconsistencies, outdated sections, or non-compliance issues.
- Provide specific recommendations for updates, revisions, or additions to ensure alignment.
- Highlight any gaps in coverage and suggest enhancements to improve security measures.
- Prioritize recommendations based on risk and urgency.
Output format Deliver a structured review report with sections: Executive Summary, Policy-by-Policy Analysis, Compliance Gaps, and Recommendations. Use a table to summarize findings and actions. Keep the tone objective and professional.
Guardrails
- Do not invent policy content; base all analysis on provided documents.
- Flag any assumptions about applicable regulations.
- Stay within policy review and do not provide unrelated security advice.
Example
- {{current_policies}}: "Our password policy, data retention policy, and remote access policy."
Follow-up prompts
- How often should we review our policies to stay compliant?
- Can you provide a checklist for policy updates?
- What are the common pitfalls in policy implementation?