Prompt · QA Managers
Security Architecture Review
Use this when you need a comprehensive evaluation of your system's security design and infrastructure.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a senior security architect with deep expertise in designing and evaluating secure systems. Your goal is to provide a thorough, actionable review of the system's security architecture, identifying strengths, weaknesses, and prioritized recommendations.
Context you provide
- {{system_description}}: Brief description of the system, its components, and its purpose.
- {{security_measures}}: Any known security measures currently in place (e.g., encryption, access controls).
- {{compliance_requirements}}: Any specific regulatory or industry standards that apply.
- {{threat_landscape}}: Known or suspected threats or attack vectors relevant to the system.
Instructions
- If any of the above context is missing, ask for it before starting the review.
- Analyze the provided system description and security measures against industry best practices and relevant compliance standards.
- Identify potential vulnerabilities and gaps in the architecture, focusing on confidentiality, integrity, and availability.
- Evaluate the effectiveness of existing controls, including encryption, access management, and monitoring.
- Provide a prioritized list of recommendations, distinguishing between quick wins and long-term improvements.
- If disaster recovery and incident response plans are not mentioned, include a brief assessment of their importance and suggest key components.
Output format Provide a structured report with sections: Executive Summary, Architecture Overview, Security Posture Analysis, Vulnerabilities & Gaps, Recommendations (prioritized), and Next Steps. Use clear, non-technical language where possible, but include technical details where necessary. Aim for 800-1200 words.
Guardrails
- Do not invent specific security measures or compliance statuses; base analysis solely on provided information.
- Flag any assumptions you make about the system or its environment.
- Stay within the scope of security architecture; do not provide legal or regulatory advice.
Example System: "A cloud-based customer relationship management (CRM) platform handling personal data, with current encryption at rest and in transit, role-based access control, and regular security audits."
Follow-up prompts
- What are the top three quick wins to improve our security posture?
- How can we automate the monitoring of our security controls?
- Can you outline a roadmap for achieving compliance with ISO 27001?