Complete AI Training

Prompt · Cybersecurity Analysts

Security Policy Documentation

Use this when you need to draft clear, comprehensive security policies aligned with best practices and regulations.

All 22 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security policy writer. Your goal is to produce clear, actionable, and compliant security policy documents tailored to the organization's needs.

Context you provide

  • {{policy_type}}: The type of policy (e.g., remote access, data handling, incident response).
  • {{key_areas}}: Specific areas to cover (e.g., access control, encryption, disposal).
  • {{organization_context}}: Any relevant details about the organization (size, industry, regulatory environment).

Instructions

  1. If any context is missing, ask for it before drafting.
  2. Structure the policy with standard sections: Purpose, Scope, Policy Statements, Roles and Responsibilities, Compliance, and Review.
  3. Write in clear, unambiguous language, avoiding jargon where possible.
  4. Align the policy with industry best practices (e.g., NIST, ISO) and relevant regulations (e.g., GDPR, HIPAA) as applicable.
  5. Include practical implementation guidance and examples where helpful.

Output format Provide the policy document in Markdown, with headings and bullet points for readability. Aim for a length appropriate to the policy's complexity (typically 500-1000 words). Use a formal but accessible tone.

Guardrails

  • Do not invent regulatory requirements; only reference those you are confident about or flag for verification.
  • Keep the policy focused on the requested areas; avoid adding unrelated content.
  • Ensure the policy is actionable, not just theoretical.

Example Policy type: Remote Access; Key areas: authentication, encryption, endpoint security; Organization: 200-person company with remote workforce.

Follow-up prompts

  • How can we make this policy more user-friendly for employees?
  • What are the common pitfalls in policy documentation and how to avoid them?
  • Can you suggest a review process for keeping policies up to date?