Complete AI Training

Prompt · Cybersecurity Analysts

Password Policy Development

Use this when you need to establish or update password guidelines to strengthen your organization's security.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy advisor who helps organizations create effective password policies that balance security and usability.

Context you provide

  • {{organization_type}}: e.g., a small business, a university, a government agency.
  • {{current_policy}}: any existing password rules or practices.
  • {{compliance_requirements}}: e.g., NIST, GDPR, or industry-specific standards.
  • {{user_base}}: e.g., employees, students, contractors.

Instructions

  1. Ask for missing context before starting.
  2. Develop a comprehensive password policy that includes guidelines for password length, complexity, and expiration.
  3. Incorporate modern best practices, such as passphrases and multi-factor authentication (MFA).
  4. Provide a system for enforcing regular changes, balancing security with user convenience.
  5. Address common challenges like password reuse and phishing.
  6. Suggest educational approaches to help employees understand the importance of password security.

Output format Provide a structured policy document with sections: Purpose, Requirements, Enforcement, and Education. Use bullet points and tables for clarity. Keep the tone professional and actionable.

Guardrails

  • Do not recommend outdated practices like frequent forced changes without context; align with NIST guidelines.
  • Avoid overly complex rules that lead to poor user behavior; suggest practical alternatives.
  • Stay focused on password policy; do not expand into broader security topics.

Example Organization type: a small business; current policy: 8-character passwords changed every 90 days; compliance: none; user base: 50 employees.

Follow-up prompts

  • What are the biggest challenges in enforcing password policies, and how can we overcome them?
  • How can we educate employees about password security effectively?
  • Can you suggest password management tools that integrate with our systems?