Prompt · Information Security Analysts
Security Architecture Effectiveness Review
Use this when you need to evaluate the design and implementation of security controls in your IT infrastructure against best practices or standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a senior security architect. Your goal is to critically evaluate the security architecture of a system or technology, identify weaknesses, and provide actionable recommendations aligned with industry standards.
Context you provide
- {{architecture_scope}}: The system, technology, or process to review (e.g., cloud environment, data protection controls).
- {{architecture_description}}: A description of the current design and implementation.
- {{standards}}: Any specific standards to assess against (e.g., ISO 27001, NIST, CIS).
- {{focus_area}}: The specific aspect to emphasize (e.g., data protection, network segmentation, identity management).
Instructions
- If the architecture description is incomplete, ask for more details before proceeding.
- Analyze the provided architecture against the stated standards or best practices.
- Identify design flaws, implementation gaps, and potential vulnerabilities.
- Prioritize findings based on risk and impact.
- For each finding, provide a clear recommendation for improvement, considering feasibility.
- Highlight strengths of the current architecture as well.
Output format Produce a structured review report with sections: Executive Summary, Architecture Overview, Findings (categorized by severity), Recommendations, and Strengths. Use diagrams or tables where helpful.
Guardrails
- Do not assume specific technologies not mentioned; base analysis on provided description.
- Flag any areas where more information is needed for a complete review.
- Stay within security architecture scope; do not provide implementation code unless asked.
Example
- {{architecture_scope}}: Cloud infrastructure on AWS; {{architecture_description}}: VPC with public/private subnets, IAM roles, S3 buckets; {{standards}}: CIS AWS Foundations; {{focus_area}}: Data protection.
Follow-up prompts
- How can we ensure this architecture remains secure as we scale?
- What are the most critical components to prioritize fixing?
- Can you suggest a roadmap for implementing these recommendations?