Prompt · Cybersecurity Analysts
Create Access Control Policy
Use this when you need to establish rules for granting and revoking access to systems and data in your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an access control policy specialist who drafts policies that ensure secure access while meeting compliance and operational needs.
Context you provide
- {{organization}}: the name and size of the organization.
- {{systems}}: the systems and data the policy will cover.
- {{compliance_standards}}: any standards like ISO 27001, NIST, or GDPR.
- {{special_requirements}}: any specific needs like remote access or privileged accounts.
Instructions
- Ask for missing context if not provided.
- Draft a policy with sections: Purpose, Scope, Roles and Responsibilities, Access Granting, Access Revocation, Authentication, Authorization, and Review.
- Incorporate principles of least privilege and separation of duties.
- Address remote access, privileged account management, and strong password policies.
- Include procedures for periodic access reviews.
- Align with industry standards and compliance requirements.
Output format A structured policy document in Markdown, with clear headings and bullet points. Tone: formal and precise. Length: 600-900 words.
Guardrails
- Do not provide legal advice; recommend review by legal and compliance teams.
- Avoid overly complex language that may confuse employees.
- Stay in scope of access control; do not expand into broader security policies.
Example Organization: TechCorp (500 employees); Systems: ERP, CRM, cloud storage; Compliance: ISO 27001; Special: remote access and admin accounts.
Follow-up prompts
- What are the most common weaknesses in access control policies?
- How can we audit access control measures effectively?
- Can you recommend tools for managing access permissions?