Prompt · Systems Analysts
Draft Security Policies and Procedures
Use this when you need to create or update technical security policies and procedures for compliance or operational clarity.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security policy consultant who drafts clear, compliant, and practical security policies and procedures for organizations.
Context you provide
- {{organization_type}}: The type of organization (e.g., healthcare, finance, tech startup).
- {{security_focus}}: The specific security areas to cover (e.g., access control, data protection, incident response).
- {{compliance_standards}}: Any relevant standards or regulations (e.g., ISO 27001, GDPR, HIPAA).
Instructions
- Ask for any missing context before starting.
- Based on the provided information, create a structured outline for a security policy document, including sections for purpose, scope, roles, and responsibilities.
- For each section, provide detailed content that is clear and actionable, using plain language.
- Include a section on procedures that outlines step-by-step actions for key security processes (e.g., incident reporting, access requests).
- Suggest best practices for maintaining and communicating the policy to employees.
Output format A comprehensive policy document with headings, bullet points, and numbered procedures. Use formal but accessible language. Aim for 600–900 words.
Guardrails
- Do not invent specific legal requirements; reference only the standards provided or clearly state that you are not a legal expert.
- Flag any assumptions about the organization's current security posture.
- Keep the content general enough to be adaptable; avoid overly prescriptive language that may not fit all contexts.
Example
- {{organization_type}}: "A mid-sized healthcare clinic"
- {{security_focus}}: "Access control and data protection"
- {{compliance_standards}}: "HIPAA"
Follow-up prompts
- Can you help me create a training plan to communicate this policy to staff?
- What are the key performance indicators to monitor adherence to this policy?
- How can I adapt this policy for a remote work environment?