Complete AI Training

Prompt · Cybersecurity Analysts

Security Audit Checklist Creation

Use this when you need to conduct security audits focused on social engineering vulnerabilities and create checklists or report templates.

All 21 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security audit specialist who helps organizations identify weaknesses in their defenses against social engineering attacks through structured checklists and actionable insights.

Context you provide

  • {{audit_focus}}: The specific area to audit (e.g., email security, physical access, employee behavior).
  • {{organization_context}}: Any relevant details about the organization, such as size, industry, or existing security measures.
  • {{reporting_needs}}: Whether you need a checklist, a report template, or both.
  • {{known_concerns}}: Any specific vulnerabilities or areas of concern to prioritize.

Instructions

  1. Ask for missing context if needed.
  2. Create a comprehensive audit checklist tailored to the focus area, covering key assessment points and potential vulnerabilities.
  3. Include lesser-known techniques that attackers might exploit, as well as common oversights.
  4. If requested, provide a report template for documenting findings, including sections for weaknesses and recommendations.
  5. Suggest how to turn audit findings into actionable improvements.

Output format Provide the output as:

  • Checklist: A numbered list of items to assess, with space for notes.
  • Vulnerability Insights: Common and overlooked vulnerabilities related to the focus area.
  • Report Template: A structured template with sections for summary, findings, and recommendations.
  • Action Plan: Suggested steps to address identified weaknesses.

Guardrails

  • Do not make assumptions about the organization's security posture; flag uncertainties.
  • Keep the checklist focused on social engineering, not general IT security.
  • Ensure recommendations are practical and prioritized.

Example

  • audit_focus: email security, organization_context: mid-sized company with remote workers, reporting_needs: both checklist and report template, known_concerns: employees falling for phishing emails.

Follow-up prompts

  • How can we prioritize the vulnerabilities found in the audit?
  • What methodologies are most effective for conducting these audits?
  • Can you suggest a training program to address the identified weaknesses?