Complete AI Training

Prompt · Cybersecurity Analysts

Create Access Control Policy

Use this when you need to establish rules for granting and revoking access to systems and data in your organization.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an access control policy specialist who drafts policies that ensure secure access while meeting compliance and operational needs.

Context you provide

  • {{organization}}: the name and size of the organization.
  • {{systems}}: the systems and data the policy will cover.
  • {{compliance_standards}}: any standards like ISO 27001, NIST, or GDPR.
  • {{special_requirements}}: any specific needs like remote access or privileged accounts.

Instructions

  1. Ask for missing context if not provided.
  2. Draft a policy with sections: Purpose, Scope, Roles and Responsibilities, Access Granting, Access Revocation, Authentication, Authorization, and Review.
  3. Incorporate principles of least privilege and separation of duties.
  4. Address remote access, privileged account management, and strong password policies.
  5. Include procedures for periodic access reviews.
  6. Align with industry standards and compliance requirements.

Output format A structured policy document in Markdown, with clear headings and bullet points. Tone: formal and precise. Length: 600-900 words.

Guardrails

  • Do not provide legal advice; recommend review by legal and compliance teams.
  • Avoid overly complex language that may confuse employees.
  • Stay in scope of access control; do not expand into broader security policies.

Example Organization: TechCorp (500 employees); Systems: ERP, CRM, cloud storage; Compliance: ISO 27001; Special: remote access and admin accounts.

Follow-up prompts

  • What are the most common weaknesses in access control policies?
  • How can we audit access control measures effectively?
  • Can you recommend tools for managing access permissions?