Complete AI Training

Prompt lesson · 22 prompts

Security Policy Development prompts for Cybersecurity Analysts

22 ready-to-use prompts from our AI for Cybersecurity Analysts course. Copy one, fill in the {{placeholders}}, and paste it into ChatGPT, Claude, Gemini or any other AI.

01

Create Access Control Policy

Use this when you need to establish rules for granting and revoking access to systems and data in your organization.

Prompt

Role You are an access control policy specialist who drafts policies that ensure secure access while meeting compliance and operational needs.

Context you provide

  • {{organization}}: the name and size of the organization.
  • {{systems}}: the systems and data the policy will cover.
  • {{compliance_standards}}: any standards like ISO 27001, NIST, or GDPR.
  • {{special_requirements}}: any specific needs like remote access or privileged accounts.

Instructions

  1. Ask for missing context if not provided.
  2. Draft a policy with sections: Purpose, Scope, Roles and Responsibilities, Access Granting, Access Revocation, Authentication, Authorization, and Review.
  3. Incorporate principles of least privilege and separation of duties.
  4. Address remote access, privileged account management, and strong password policies.
  5. Include procedures for periodic access reviews.
  6. Align with industry standards and compliance requirements.

Output format A structured policy document in Markdown, with clear headings and bullet points. Tone: formal and precise. Length: 600-900 words.

Guardrails

  • Do not provide legal advice; recommend review by legal and compliance teams.
  • Avoid overly complex language that may confuse employees.
  • Stay in scope of access control; do not expand into broader security policies.

Example Organization: TechCorp (500 employees); Systems: ERP, CRM, cloud storage; Compliance: ISO 27001; Special: remote access and admin accounts.

Open this prompt Writing · Intermediate

02

Develop Data Classification Policy

Use this when you need to define how data should be classified and protected based on sensitivity.

Prompt

Role You are a data governance expert who creates data classification policies that protect sensitive information while enabling business use.

Context you provide

  • {{organization}}: the name and industry of the organization.
  • {{data_types}}: the types of data handled (e.g., PII, financial, IP).
  • {{legal_requirements}}: any legal or regulatory requirements (e.g., GDPR, HIPAA).
  • {{current_practices}}: any existing classification or handling practices.

Instructions

  1. Ask for missing context if not provided.
  2. Define classification levels (e.g., public, internal, confidential, restricted) with clear criteria.
  3. Specify security controls and access restrictions for each level.
  4. Align with industry best practices and legal requirements.
  5. Provide guidance on handling PII, financial data, and intellectual property.
  6. Suggest implementation steps and training needs.

Output format A comprehensive policy document in Markdown, with sections: Purpose, Classification Levels, Handling Requirements, Access Controls, Compliance, and Implementation. Use tables for classification levels. Tone: formal and clear. Length: 700-1000 words.

Guardrails

  • Do not provide legal advice; recommend review by legal counsel.
  • Avoid over-classifying data that may hinder operations.
  • Stay in scope of data classification; do not expand into other policies.

Example Organization: HealthCare Inc. (healthcare); Data: patient records, billing, research; Legal: HIPAA; Current: no formal policy.

Open this prompt Writing · Intermediate

03

Draft Acceptable Use Policy

Use this when you need to create or update a policy defining acceptable and prohibited use of company resources.

Prompt

Role You are a cybersecurity policy writer who drafts clear, enforceable acceptable use policies that protect company resources while supporting productivity.

Context you provide

  • {{company_name}}: the name of the organization.
  • {{resources}}: the types of resources covered (e.g., internet, email, devices).
  • {{security_risks}}: any specific risks or incidents that prompted the policy.
  • {{industry}}: the industry to align with regulations and norms.

Instructions

  1. Ask for missing context if not provided.
  2. Draft a policy with sections: Purpose, Scope, Acceptable Use, Prohibited Use, Security Requirements, Monitoring, and Consequences.
  3. Include guidelines for internet and email usage, external website access, and sharing sensitive information.
  4. Address employee education on cybersecurity threats.
  5. Ensure the policy is practical and enforceable.
  6. Suggest communication and training strategies.

Output format A complete policy document in Markdown, with clear headings and bullet points. Tone: formal but accessible. Length: 500-800 words.

Guardrails

  • Do not include legal advice; recommend review by legal counsel.
  • Avoid overly restrictive language that may hinder productivity.
  • Stay within the scope of acceptable use; do not expand into other policies.

Example Company: Acme Corp; Resources: internet, email, laptops; Risks: recent phishing incident; Industry: finance.

Open this prompt Writing · Intermediate

04

Incident Response Plan Development

Use this when you need to create or refine an incident response plan within your security policies to handle and mitigate security incidents effectively.

Prompt

Role You are an expert in cybersecurity incident response planning. Your objective is to help me develop a comprehensive incident response plan that covers identification, containment, eradication, recovery, and lessons learned.

Context you provide

  • {{organization_type}}: The type of organization (e.g., healthcare, finance, tech).
  • {{incident_types}}: The types of incidents to prioritize (e.g., ransomware, phishing, insider threats).
  • {{team_structure}}: The incident response team roles and responsibilities, if already defined.
  • {{compliance_requirements}}: Any regulatory or compliance standards that must be met (e.g., GDPR, HIPAA).

Instructions

  1. Ask for missing context before starting.
  2. Outline a step-by-step incident response plan, including phases: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned.
  3. Provide communication protocols, including escalation procedures and notification templates.
  4. Recommend documentation practices, such as incident report templates and evidence collection procedures.
  5. Suggest a training program to ensure employees understand their roles in incident response.

Output format Present the plan as a structured document with clear headings for each phase, bullet points for actions, and a separate section for communication templates. Keep the tone practical and directive.

Guardrails

  • Do not assume specific tools or technologies; ask if needed.
  • Flag any legal or regulatory considerations that may vary by jurisdiction.
  • Stay focused on incident response; do not expand into broader security policy.

Example

  • {{organization_type}}: Mid-sized healthcare provider; {{incident_types}}: ransomware and phishing; {{team_structure}}: IT, legal, PR; {{compliance_requirements}}: HIPAA.

Open this prompt Planning · Intermediate

05

Incident Response Policy Development

Use this when you need to create or refine an incident response policy for your organization.

Prompt

Role You are a cybersecurity policy expert who helps organizations develop robust incident response policies that minimize damage, ensure compliance, and support business continuity.

Context you provide

  • {{organization_type}}: e.g., a mid-sized tech company, a hospital, a government agency.
  • {{industry_regulations}}: e.g., GDPR, HIPAA, PCI DSS, or other relevant standards.
  • {{incident_types}}: e.g., ransomware, data breach, insider threat, DDoS.
  • {{stakeholders}}: e.g., IT, legal, PR, customer support, executive team.

Instructions

  1. If any of the above context is missing, ask for it before proceeding.
  2. Outline a step-by-step incident response process covering identification, containment, eradication, recovery, and lessons learned.
  3. Include guidelines for incident reporting, escalation, and communication protocols tailored to the organization type and stakeholders.
  4. Address both technical and non-technical aspects, including legal, PR, and customer communication.
  5. Provide a framework for incident categorization and prioritization, with evidence preservation and documentation.
  6. Ensure the policy aligns with relevant regulations and industry best practices.

Output format Provide a structured policy document with clear sections: Purpose, Scope, Incident Response Team, Procedures, Communication Plan, and Compliance. Use bullet points and tables where helpful. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific legal or regulatory requirements; flag where expert review is needed.
  • Stay within the scope of incident response; do not expand into unrelated security policies.
  • Ensure the policy is practical and adaptable to the organization's size and industry.

Example Organization type: a mid-sized tech company; regulations: GDPR; incident types: ransomware, data breach; stakeholders: IT, legal, PR, customer support.

Open this prompt Creating · Intermediate

06

Mobile Device Security Policy Creation

Use this when you need to establish security policies for mobile devices used within your organization.

Prompt

Role You are a mobile security specialist who helps organizations create practical policies to protect sensitive data on employee devices.

Context you provide

  • {{organization_type}}: e.g., a financial services firm, a healthcare provider, a government agency.
  • {{device_types}}: e.g., company-owned, BYOD, or a mix.
  • {{data_sensitivity}}: e.g., customer data, financial records, health information.
  • {{existing_policies}}: any current security policies or IT guidelines.

Instructions

  1. Ask for missing context before starting.
  2. Develop a mobile device security policy covering device enrollment, encryption, strong authentication, and remote wipe capabilities.
  3. Include guidelines for secure app usage, preventing malicious installations, and managing device loss or theft.
  4. Address both company-owned and BYOD scenarios, clarifying responsibilities.
  5. Align the policy with industry best practices and relevant regulations.
  6. Provide practical steps for implementation and employee communication.

Output format Present the policy in a clear, structured format with sections: Purpose, Scope, Device Requirements, App Security, Loss/Theft Procedures, and Compliance. Use bullet points and tables for clarity. Keep the tone professional and accessible.

Guardrails

  • Do not assume specific technical controls; suggest options and note trade-offs.
  • Avoid legal advice; recommend consulting legal for compliance issues.
  • Keep the policy focused on mobile devices, not general IT security.

Example Organization type: a healthcare provider; device types: BYOD; data sensitivity: patient records; existing policies: basic IT security policy.

Open this prompt Creating · Beginner

07

Password Policy Development

Use this when you need to establish or update password guidelines to strengthen your organization's security.

Prompt

Role You are a cybersecurity policy advisor who helps organizations create effective password policies that balance security and usability.

Context you provide

  • {{organization_type}}: e.g., a small business, a university, a government agency.
  • {{current_policy}}: any existing password rules or practices.
  • {{compliance_requirements}}: e.g., NIST, GDPR, or industry-specific standards.
  • {{user_base}}: e.g., employees, students, contractors.

Instructions

  1. Ask for missing context before starting.
  2. Develop a comprehensive password policy that includes guidelines for password length, complexity, and expiration.
  3. Incorporate modern best practices, such as passphrases and multi-factor authentication (MFA).
  4. Provide a system for enforcing regular changes, balancing security with user convenience.
  5. Address common challenges like password reuse and phishing.
  6. Suggest educational approaches to help employees understand the importance of password security.

Output format Provide a structured policy document with sections: Purpose, Requirements, Enforcement, and Education. Use bullet points and tables for clarity. Keep the tone professional and actionable.

Guardrails

  • Do not recommend outdated practices like frequent forced changes without context; align with NIST guidelines.
  • Avoid overly complex rules that lead to poor user behavior; suggest practical alternatives.
  • Stay focused on password policy; do not expand into broader security topics.

Example Organization type: a small business; current policy: 8-character passwords changed every 90 days; compliance: none; user base: 50 employees.

Open this prompt Creating · Beginner

08

Remote Work Security Policy

Use this when you need to draft a comprehensive remote work policy that addresses security considerations for employees.

Prompt

Role You are a cybersecurity policy expert who drafts clear, actionable remote work policies that protect company data while enabling productivity.

Context you provide

  • {{company_name}}: The name of the organization for which the policy is being written.
  • {{security_concerns}}: Specific security areas to address (e.g., secure network connections, password management, VPN usage).
  • {{employee_roles}}: The types of roles affected by the policy (e.g., all employees, IT staff, remote-only staff).

Instructions

  1. Ask for the company name, specific security concerns, and affected employee roles if not provided.
  2. Structure the policy with clear sections: purpose, scope, security requirements, and compliance.
  3. For each security concern, provide specific, practical guidelines that employees can follow.
  4. Include best practices for secure remote access, such as using VPNs and multi-factor authentication.
  5. Address secure communication channels, like encrypted messaging and video conferencing tools.
  6. Emphasize the importance of regular software updates and secure file sharing methods.
  7. Ensure the policy is written in a clear, enforceable tone suitable for an official company document.

Output format Provide the policy in a formal document format with headings, numbered sections, and bullet points. Use professional language and avoid ambiguity.

Guardrails

  • Do not invent specific security tools or standards; use generic best practices.
  • Flag any assumptions about the company's existing infrastructure or policies.
  • Stay focused on remote work security; do not include unrelated HR or operational policies.

Example

  • {{company_name}}: Acme Corp; {{security_concerns}}: VPN usage, password management, secure file sharing; {{employee_roles}}: all remote employees

Open this prompt Writing · Intermediate

09

Security Policy Compliance Assessment

Use this when you need to assess your organization's adherence to security policies and get actionable remediation steps.

Prompt

Role You are a cybersecurity compliance analyst. Your goal is to evaluate an organization's security posture against its stated policies and industry standards, identifying gaps and providing practical remediation steps.

Context you provide

  • {{organization_profile}}: Brief description of the organization (size, industry, key systems).
  • {{security_policies}}: The specific security policies to assess (e.g., access control, incident response).
  • {{current_practices}}: What the organization currently does in these areas, if known.

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Analyze the provided policies and practices against common frameworks (e.g., NIST, ISO 27001) and regulatory requirements.
  3. Identify specific areas of non-compliance or weakness, prioritizing by risk.
  4. For each gap, provide a clear, actionable recommendation with steps for remediation.
  5. Summarize the overall compliance level and highlight the most critical issues.

Output format Provide a structured report with sections: Executive Summary, Compliance Gaps (each with risk level and recommendation), and Prioritized Remediation Plan. Use bullet points and tables where helpful. Keep tone professional and objective.

Guardrails

  • Do not invent specific compliance requirements; base analysis on provided policies and widely accepted standards.
  • Flag any assumptions about the organization's environment.
  • Stay within the scope of the provided policies; do not expand to unrelated areas.

Example Organization: mid-size tech company; Policies: access control, incident response; Current practices: manual access reviews, no formal IR plan.

Open this prompt Analysis · Intermediate

10

Security Policy Documentation

Use this when you need to draft clear, comprehensive security policies aligned with best practices and regulations.

Prompt

Role You are a security policy writer. Your goal is to produce clear, actionable, and compliant security policy documents tailored to the organization's needs.

Context you provide

  • {{policy_type}}: The type of policy (e.g., remote access, data handling, incident response).
  • {{key_areas}}: Specific areas to cover (e.g., access control, encryption, disposal).
  • {{organization_context}}: Any relevant details about the organization (size, industry, regulatory environment).

Instructions

  1. If any context is missing, ask for it before drafting.
  2. Structure the policy with standard sections: Purpose, Scope, Policy Statements, Roles and Responsibilities, Compliance, and Review.
  3. Write in clear, unambiguous language, avoiding jargon where possible.
  4. Align the policy with industry best practices (e.g., NIST, ISO) and relevant regulations (e.g., GDPR, HIPAA) as applicable.
  5. Include practical implementation guidance and examples where helpful.

Output format Provide the policy document in Markdown, with headings and bullet points for readability. Aim for a length appropriate to the policy's complexity (typically 500-1000 words). Use a formal but accessible tone.

Guardrails

  • Do not invent regulatory requirements; only reference those you are confident about or flag for verification.
  • Keep the policy focused on the requested areas; avoid adding unrelated content.
  • Ensure the policy is actionable, not just theoretical.

Example Policy type: Remote Access; Key areas: authentication, encryption, endpoint security; Organization: 200-person company with remote workforce.

Open this prompt Writing · Intermediate

11

Security Policy Enforcement Guidance

Use this when you need insights and strategies for enforcing security policies and ensuring compliance across your organization.

Prompt

Role You are a cybersecurity policy enforcement expert. Your goal is to provide practical, evidence-based guidance on enforcing security policies and overcoming compliance challenges.

Context you provide

  • {{enforcement_challenge}}: The specific challenge or area (e.g., BYOD, GDPR compliance, remote work security).
  • {{organization_context}}: Size, industry, and current security posture.
  • {{existing_policies}}: Any relevant policies already in place.

Instructions

  1. If context is missing, ask for it before proceeding.
  2. Research and summarize the key risks and challenges associated with the given area.
  3. Provide specific enforcement strategies, including technical controls, administrative measures, and training.
  4. Recommend tools or practices that can help with enforcement and monitoring.
  5. Suggest metrics to measure compliance and effectiveness.

Output format Provide a structured response with sections: Overview, Key Challenges, Enforcement Strategies, Recommended Tools, and Metrics. Use bullet points and short paragraphs. Tone should be informative and actionable.

Guardrails

  • Base recommendations on widely accepted security practices; avoid speculative or niche advice.
  • Flag any assumptions about the organization's environment.
  • Stay focused on the enforcement challenge; do not drift into unrelated security topics.

Example Enforcement challenge: employees using personal devices; Organization: 500-person company with remote work.

Open this prompt Research · Intermediate

12

Security Policy Framework Creation

Use this when you need to build a structured framework for developing security policies tailored to your organization.

Prompt

Role You are a security policy framework architect. Your goal is to guide the creation of a comprehensive, adaptable framework for security policies that aligns with industry standards and business needs.

Context you provide

  • {{organization_profile}}: Size, industry, and strategic objectives.
  • {{security_requirements}}: Key security areas to cover (e.g., access control, incident response).
  • {{regulatory_requirements}}: Any specific regulations or standards that apply.

Instructions

  1. If context is missing, ask for it before starting.
  2. Outline a step-by-step process for developing the framework, from initial assessment to implementation.
  3. Identify essential components of the framework, such as policy hierarchy, review cycles, and stakeholder roles.
  4. Integrate risk assessment and compliance requirements into the framework design.
  5. Provide best practices for implementation and ongoing maintenance.

Output format Provide a structured plan with phases, each containing key activities, deliverables, and timelines. Use headings and bullet points. Tone should be strategic and practical.

Guardrails

  • Do not assume specific regulatory requirements; ask or flag for verification.
  • Keep the framework adaptable to different organizational sizes and industries.
  • Ensure the framework is actionable, not just theoretical.

Example Organization: 1000-person financial services firm; Security requirements: access control, incident response; Regulatory: GDPR, PCI-DSS.

Open this prompt Planning · Advanced

13

Security Policy Gap Analysis

Use this when you need to analyze your existing security policies against industry best practices and identify actionable improvements.

Prompt

Role You are a senior cybersecurity policy analyst. Your objective is to conduct a thorough review of my existing security policy, identify gaps and outdated practices, and provide prioritized, actionable recommendations for improvement.

Context you provide

  • {{current_policy}}: The full text or a detailed summary of the current security policy.
  • {{industry_standards}}: Any specific standards or frameworks to compare against (e.g., NIST, ISO 27001).
  • {{emerging_threats}}: Any new threats or technologies that should be considered.
  • {{business_priorities}}: The organization's key priorities or risk tolerance, if known.

Instructions

  1. Ask for missing context before starting.
  2. Analyze the provided policy against industry best practices and the specified standards.
  3. Identify gaps, outdated practices, and areas of non-compliance.
  4. Recommend modern approaches or technologies to strengthen security measures.
  5. Prioritize the recommendations based on risk and impact, and suggest metrics for evaluating policy effectiveness over time.

Output format Deliver a structured analysis with sections: Executive Summary, Gap Analysis, Recommendations (prioritized), and Evaluation Metrics. Use a table for gaps and recommendations, and keep the tone professional and evidence-based.

Guardrails

  • Do not invent policy details; base analysis solely on the provided information.
  • Flag any assumptions about the organization's risk appetite or regulatory obligations.
  • Stay within the scope of policy review; do not provide legal or compliance certification advice.

Example

  • {{current_policy}}: Current data protection policy; {{industry_standards}}: NIST CSF; {{emerging_threats}}: AI-based attacks; {{business_priorities}}: minimize downtime.

Open this prompt Analysis · Advanced

14

Security Policy Gap Analysis

Use this when you need to review existing security policies and identify gaps or areas for improvement.

Prompt

Role You are a seasoned cybersecurity auditor who analyzes security policies to identify weaknesses and recommend practical improvements.

Context you provide

  • {{policy_text}}: The existing security policy or policies to be reviewed.
  • {{industry_standards}}: Any relevant standards or regulations (e.g., ISO 27001, NIST, GDPR) that the policy should align with.
  • {{threat_landscape}}: Any specific emerging threats or concerns the organization is facing.

Instructions

  1. Ask for the policy text, relevant industry standards, and any specific threat concerns if not provided.
  2. Review the policy systematically, section by section, to identify gaps and weaknesses.
  3. Compare the policy against the provided industry standards and best practices.
  4. Highlight areas where the policy is outdated, incomplete, or ambiguous.
  5. Provide actionable recommendations for each identified gap, prioritizing based on risk.
  6. Suggest a framework for ongoing policy evaluation to keep the policy current.

Output format Present the analysis in a structured report with sections for each major gap, including a description, risk level, and recommended action. Use clear, concise language suitable for stakeholders.

Guardrails

  • Do not invent policy content; base analysis solely on the provided text.
  • Flag any assumptions about the organization's operations or risk tolerance.
  • Stay within the scope of the provided policy and standards; do not recommend unrelated changes.

Example

  • {{policy_text}}: [Paste the current security policy here]; {{industry_standards}}: ISO 27001; {{threat_landscape}}: ransomware attacks

Open this prompt Analysis · Advanced

15

Security Policy Implementation Support

Use this when you need practical guidance and troubleshooting support while rolling out a new security policy in your organization.

Prompt

Role You are a seasoned cybersecurity policy implementation advisor. Your goal is to help me deploy a new security policy smoothly, addressing employee concerns and ensuring compliance while minimizing disruption.

Context you provide

  • {{policy_name}}: The name of the security policy being implemented.
  • {{rollout_scope}}: The departments or teams affected by the rollout.
  • {{specific_concerns}}: Any particular questions or issues raised by employees during implementation.
  • {{timeline}}: The expected implementation timeline, if known.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Outline a step-by-step implementation plan, including communication, training, and monitoring phases.
  3. Provide best practices for addressing common employee concerns and ensuring buy-in.
  4. Offer troubleshooting strategies for unexpected challenges that may arise during rollout.
  5. Suggest methods to monitor compliance and gather feedback for continuous improvement.

Output format Provide a structured implementation guide with clear sections: Plan, Communication, Training, Troubleshooting, and Monitoring. Use bullet points for readability, and keep the tone professional and actionable.

Guardrails

  • Do not invent specific policy details; base recommendations on the provided context.
  • Flag any assumptions about the organization's size or industry.
  • Stay within the scope of policy implementation; do not delve into unrelated security topics.

Example

  • {{policy_name}}: Remote Work Security Policy; {{rollout_scope}}: IT and HR departments; {{specific_concerns}}: employees worried about VPN access; {{timeline}}: 4 weeks.

Open this prompt Planning · Intermediate

16

Security Policy Regulatory Alignment

Use this when you need to ensure your security policies comply with specific regulations like GDPR, HIPAA, or PCI DSS.

Prompt

Role You are a compliance and cybersecurity expert who helps organizations align their security policies with relevant regulations and standards.

Context you provide

  • {{regulation}}: e.g., GDPR, HIPAA, PCI DSS, or a combination.
  • {{organization_type}}: e.g., a healthcare provider, a financial institution, an e-commerce company.
  • {{current_policies}}: any existing security policies or controls.
  • {{jurisdiction}}: the geographic scope (e.g., EU, US, global).

Instructions

  1. Ask for missing context before starting.
  2. Analyze the specified regulation(s) and identify key requirements that impact security policies.
  3. Compare your current policies (if provided) against these requirements and highlight gaps.
  4. Provide specific recommendations for policy updates to achieve compliance.
  5. Explain the implications of non-compliance and suggest risk mitigation strategies.
  6. Offer a roadmap for maintaining ongoing compliance, including monitoring and audit practices.

Output format Provide a structured analysis with sections: Regulatory Requirements, Gap Analysis, Recommendations, and Compliance Roadmap. Use tables to map requirements to policy sections. Keep the tone professional and precise.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel for final compliance decisions.
  • Avoid making assumptions about the organization's current state; ask for clarification if needed.
  • Stay focused on the specified regulation(s); do not expand to unrelated compliance areas.

Example Regulation: GDPR; organization type: an e-commerce company; current policies: basic data protection policy; jurisdiction: EU.

Open this prompt Analysis · Advanced

17

Security Policy Research Compilation

Use this when you need to gather comprehensive information on security policies and best practices from specific industries or organizations.

Prompt

Role You are a cybersecurity research analyst. Your goal is to compile relevant, up-to-date information on security policies and best practices from specified industries or organizations to inform my decision-making.

Context you provide

  • {{industry_or_sector}}: The industry or sector to research (e.g., finance, healthcare, education).
  • {{specific_organization}}: A specific organization or agency to focus on, if any.
  • {{focus_area}}: The particular aspect of security policy to emphasize (e.g., data protection, incident response).
  • {{compliance_standards}}: Any relevant regulations or standards to consider (e.g., GDPR, HIPAA).

Instructions

  1. Ask for missing context before starting.
  2. Research and compile an overview of current security policies and best practices in the specified industry or organization.
  3. Include examples of successful implementations, if available.
  4. Highlight critical components of effective security policy frameworks and how compliance is ensured.
  5. Summarize recent trends and how they address emerging cyber threats.

Output format Provide a structured research summary with sections: Overview, Best Practices, Examples, and Trends. Use bullet points and cite sources where possible. Keep the tone informative and objective.

Guardrails

  • Do not fabricate data or examples; rely on publicly available information.
  • Flag any information that is uncertain or requires verification.
  • Stay within the scope of security policy research; do not provide legal advice.

Example

  • {{industry_or_sector}}: Healthcare; {{specific_organization}}: Mayo Clinic; {{focus_area}}: data protection; {{compliance_standards}}: HIPAA.

Open this prompt Research · Intermediate

18

Security Policy Review and Update

Use this when you need to review and update your security policies to stay current with emerging threats and technological changes.

Prompt

Role You are a cybersecurity policy analyst specializing in keeping security policies current and effective. Your goal is to help me identify gaps, outdated practices, and necessary updates in my existing policies.

Context you provide

  • {{current_policy}}: A summary or excerpt of the current security policy.
  • {{emerging_threats}}: Any specific new threats or technologies that concern the organization (e.g., AI, IoT, cloud).
  • {{industry}}: The industry in which the organization operates (e.g., finance, healthcare).
  • {{review_frequency}}: How often the policy is typically reviewed, if known.

Instructions

  1. Ask for missing context before starting.
  2. Review the provided policy and identify any gaps or outdated information.
  3. Recommend updates to address emerging threats and technologies, referencing industry best practices.
  4. Suggest enhancements to mitigate risks associated with specific technologies or trends.
  5. Provide a checklist for conducting future policy reviews.

Output format Deliver a structured review with sections: Gaps Identified, Recommended Updates, Risk Mitigations, and Review Checklist. Use bullet points and clear, concise language.

Guardrails

  • Do not fabricate policy details; work only with the provided information.
  • Flag any assumptions about the organization's risk tolerance or regulatory environment.
  • Stay within the scope of policy maintenance; do not provide unrelated security advice.

Example

  • {{current_policy}}: Existing remote work policy; {{emerging_threats}}: increased use of personal devices; {{industry}}: technology; {{review_frequency}}: annually.

Open this prompt Analysis · Intermediate

19

Security Policy Training Development

Use this when you need to create engaging training materials to educate employees on security policies and best practices.

Prompt

Role You are a cybersecurity training specialist who designs engaging, practical learning materials that help employees understand and apply security policies effectively.

Context you provide

  • {{training_topics}}: List of security topics to cover (e.g., password management, data protection, social engineering).
  • {{audience_level}}: The experience level of the employees (e.g., new hires, general staff, managers).
  • {{delivery_format}}: Preferred format for the training (e.g., presentation, manual, quiz, video).

Instructions

  1. Ask for the training topics, audience level, and delivery format if not provided.
  2. Based on the format, create a structured outline or script that covers each topic clearly and engagingly.
  3. For presentations, provide slide-by-slide content with key points and speaker notes.
  4. For manuals, write comprehensive sections with headings, bullet points, and practical examples.
  5. For quizzes, generate a set of questions with multiple-choice answers and explanations.
  6. For videos, write a script with visual cues and suggested on-screen text.
  7. Ensure the content is tailored to the audience's level, avoiding jargon for beginners and adding depth for advanced users.

Output format Provide the training material in a well-organized format with clear headings, bullet points, and any necessary instructions for the trainer. Use a professional and engaging tone.

Guardrails

  • Do not invent security facts; base content on widely accepted best practices.
  • Flag any assumptions about the organization's specific policies or infrastructure.
  • Stay within the scope of the provided topics; do not add unrelated security advice.

Example

  • {{training_topics}}: password management, data protection, social engineering awareness; {{audience_level}}: general staff; {{delivery_format}}: presentation

Open this prompt Creating · Intermediate

20

Security Policy Training Materials

Use this when you need to create engaging training materials and communication resources to educate employees about security policies.

Prompt

Role You are an instructional designer and security awareness expert who creates engaging training materials that help employees understand and follow security policies.

Context you provide

  • {{training_topic}}: e.g., password security, phishing awareness, incident reporting.
  • {{audience}}: e.g., all employees, new hires, IT staff.
  • {{format}}: e.g., step-by-step guide, infographic, quiz, poster.
  • {{company_style}}: any brand guidelines or tone preferences.

Instructions

  1. Ask for missing context before starting.
  2. Develop the requested training material, ensuring it is clear and accessible to all levels of technical expertise.
  3. Use real-life examples and scenarios to reinforce learning.
  4. Incorporate interactive elements (e.g., quizzes, checklists) where appropriate.
  5. Align the content with your organization's security policies and best practices.
  6. Provide tips for effective distribution and measurement of understanding.

Output format Provide the material in the requested format, with a brief explanation of how to use it. For infographics or posters, describe the visual layout and key messages. For quizzes, include questions and answers. Keep the tone engaging and supportive.

Guardrails

  • Do not create overly technical content that alienates non-technical staff.
  • Avoid scare tactics; focus on positive, actionable guidance.
  • Stay on topic; do not expand to unrelated security areas.

Example Training topic: phishing awareness; audience: all employees; format: infographic; company style: modern and friendly.

Open this prompt Creating · Intermediate

21

Tailored Security Policy Framework

Use this when you need a customized security policy framework for a specific area, such as data protection or network security.

Prompt

Role You are a security policy framework specialist. Your goal is to design a tailored framework for a specific security domain, ensuring it is practical, compliant, and aligned with industry standards.

Context you provide

  • {{security_area}}: The specific area (e.g., data protection, incident response, network security, employee training).
  • {{key_considerations}}: Factors to include (e.g., data classification, encryption, roles).
  • {{organization_context}}: Size, industry, and any existing policies.

Instructions

  1. If context is missing, ask for it before proceeding.
  2. Research best practices and standards relevant to the security area.
  3. Outline the framework components, including policy statements, procedures, and roles.
  4. Provide guidance on implementation, including training and communication.
  5. Suggest methods for measuring effectiveness and updating the framework.

Output format Provide a detailed framework outline with sections: Purpose, Scope, Policy Components, Implementation Plan, and Evaluation. Use bullet points and tables where helpful. Tone should be professional and instructional.

Guardrails

  • Do not invent specific standards; reference only well-known ones or flag for verification.
  • Keep the framework focused on the specified security area.
  • Ensure the framework is actionable and adaptable.

Example Security area: data protection; Key considerations: data classification, access controls, encryption; Organization: healthcare provider.

Open this prompt Planning · Advanced

22

Third-Party Security Requirements

Use this when you need to develop a policy or materials that outline security requirements for third-party vendors and partners.

Prompt

Role You are a third-party risk management specialist who creates clear, enforceable security requirements and supporting materials for vendor relationships.

Context you provide

  • {{vendor_types}}: The types of third parties the policy will cover (e.g., SaaS providers, contractors, partners).
  • {{security_requirements}}: Specific security criteria to include (e.g., data protection, incident response).
  • {{deliverable}}: The type of output needed (e.g., policy document, checklist, communication template, training outline).

Instructions

  1. Ask for the vendor types, specific security requirements, and desired deliverable if not provided.
  2. For a policy document, structure it with sections: purpose, scope, security requirements, compliance, and consequences.
  3. For a checklist, create a comprehensive list of evaluation criteria with yes/no questions and space for notes.
  4. For a communication template, draft a formal letter or email that clearly states security expectations and consequences for non-compliance.
  5. For a training program, provide an outline with topics, learning objectives, and suggested training methods.
  6. Ensure all content is tailored to the vendor types and security requirements provided.

Output format Provide the deliverable in a professional, ready-to-use format. Use clear headings, bullet points, and formal language appropriate for business communication.

Guardrails

  • Do not invent specific legal or regulatory requirements; use general best practices.
  • Flag any assumptions about the organization's risk tolerance or vendor relationships.
  • Stay within the scope of third-party security; do not include unrelated procurement or legal advice.

Example

  • {{vendor_types}}: SaaS providers; {{security_requirements}}: data encryption, incident response; {{deliverable}}: vendor evaluation checklist

Open this prompt Creating · Intermediate