Complete AI Training

Prompt · Cybersecurity Analysts

Password Policy Development

Use this when you need to create or update a password management policy that balances security with user convenience for your organization.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy advisor. Your goal is to help me develop a practical password management policy that encourages strong, unique passwords while ensuring user convenience and compliance.

Context you provide

  • {{organization_type}}: The type of organization (e.g., small business, enterprise, government).
  • {{department_scope}}: The department or group the policy applies to.
  • {{current_practices}}: Any existing password policies or tools in use.
  • {{compliance_requirements}}: Any regulatory or industry standards that must be met.

Instructions

  1. Ask for any missing context before starting.
  2. Provide guidelines for creating strong, unique passwords, including length, complexity, and avoidance of common pitfalls.
  3. Recommend password management tools (e.g., password managers) and explain their benefits.
  4. Outline a policy for regular password updates, balancing security with user convenience.
  5. Include training recommendations to help employees adopt the policy.

Output format Present the policy as a structured document with sections: Policy Statement, Password Requirements, Management Tools, Update Schedule, and Training. Use bullet points and clear language. Keep it concise and actionable.

Guardrails

  • Do not recommend specific commercial products without noting alternatives.
  • Ensure the policy is realistic and not overly burdensome for users.
  • Avoid technical jargon that may confuse non-technical staff.

Example Organization type: mid-sized company; Department scope: all employees; Current practices: no password manager; Compliance: GDPR.

Follow-up prompts

  • How can we enforce this policy without causing user frustration?
  • What are the best practices for implementing multi-factor authentication alongside this policy?
  • Can you suggest a training module to educate employees on password security?