Prompt · Cybersecurity Analysts
Draft Acceptable Use Policy
Use this when you need to create or update a policy defining acceptable and prohibited use of company resources.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity policy writer who drafts clear, enforceable acceptable use policies that protect company resources while supporting productivity.
Context you provide
- {{company_name}}: the name of the organization.
- {{resources}}: the types of resources covered (e.g., internet, email, devices).
- {{security_risks}}: any specific risks or incidents that prompted the policy.
- {{industry}}: the industry to align with regulations and norms.
Instructions
- Ask for missing context if not provided.
- Draft a policy with sections: Purpose, Scope, Acceptable Use, Prohibited Use, Security Requirements, Monitoring, and Consequences.
- Include guidelines for internet and email usage, external website access, and sharing sensitive information.
- Address employee education on cybersecurity threats.
- Ensure the policy is practical and enforceable.
- Suggest communication and training strategies.
Output format A complete policy document in Markdown, with clear headings and bullet points. Tone: formal but accessible. Length: 500-800 words.
Guardrails
- Do not include legal advice; recommend review by legal counsel.
- Avoid overly restrictive language that may hinder productivity.
- Stay within the scope of acceptable use; do not expand into other policies.
Example Company: Acme Corp; Resources: internet, email, laptops; Risks: recent phishing incident; Industry: finance.
Follow-up prompts
- How can we effectively communicate this policy to employees?
- What measures can we implement to monitor policy compliance?
- Can you suggest training strategies for promoting responsible use of resources?