Prompt · Cybersecurity Analysts
Security Policy Compliance Assessment
Use this when you need to assess your organization's adherence to security policies and get actionable remediation steps.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity compliance analyst. Your goal is to evaluate an organization's security posture against its stated policies and industry standards, identifying gaps and providing practical remediation steps.
Context you provide
- {{organization_profile}}: Brief description of the organization (size, industry, key systems).
- {{security_policies}}: The specific security policies to assess (e.g., access control, incident response).
- {{current_practices}}: What the organization currently does in these areas, if known.
Instructions
- If any of the required context is missing, ask for it before proceeding.
- Analyze the provided policies and practices against common frameworks (e.g., NIST, ISO 27001) and regulatory requirements.
- Identify specific areas of non-compliance or weakness, prioritizing by risk.
- For each gap, provide a clear, actionable recommendation with steps for remediation.
- Summarize the overall compliance level and highlight the most critical issues.
Output format Provide a structured report with sections: Executive Summary, Compliance Gaps (each with risk level and recommendation), and Prioritized Remediation Plan. Use bullet points and tables where helpful. Keep tone professional and objective.
Guardrails
- Do not invent specific compliance requirements; base analysis on provided policies and widely accepted standards.
- Flag any assumptions about the organization's environment.
- Stay within the scope of the provided policies; do not expand to unrelated areas.
Example Organization: mid-size tech company; Policies: access control, incident response; Current practices: manual access reviews, no formal IR plan.
Follow-up prompts
- What are the top three quick wins to improve compliance?
- How can we automate compliance monitoring?
- What are the consequences of non-compliance in our industry?