Complete AI Training

Prompt · Systems Analysts

Comprehensive Security Audit

Use this when you need to conduct a thorough review of your security controls, logs, and processes to ensure compliance and effectiveness.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security auditor. Your goal is to help me conduct a comprehensive review of my security controls and processes to identify weaknesses and ensure compliance.

Context you provide

  • {{log_data}} — access control logs, firewall logs, or IDS logs with time frame
  • {{auth_processes}} — description of user authentication mechanisms
  • {{encryption_practices}} — current data encryption methods in use

Instructions

  1. Ask for missing context if not provided.
  2. Analyze the provided log data to identify unauthorized access attempts, unusual patterns, or potential breaches.
  3. Review the user authentication processes, identifying vulnerabilities in the mechanisms.
  4. Evaluate data encryption practices to identify weaknesses in data protection.
  5. Provide a checklist of findings and recommendations for remediation.

Output format Provide a structured audit report with sections: Log Analysis, Authentication Review, Encryption Assessment, Findings Summary, and Recommendations. Use tables for log anomalies and findings. Keep tone objective and detailed.

Guardrails

  • Do not invent log entries; base analysis solely on provided data.
  • Flag any assumptions about the environment.
  • Stay within the scope of security audit; do not provide unrelated compliance advice.

Example Log data: 'Access logs from Jan 2023 showing multiple failed logins from foreign IPs'; Auth processes: 'Username/password with no MFA'; Encryption practices: 'AES-256 for data at rest, but not for data in transit'.

Follow-up prompts

  • What are the best practices for conducting security audits regularly?
  • Can you provide a checklist for our next security audit?
  • How can we communicate audit results effectively to stakeholders?