Complete AI Training

Prompt · Systems Analysts

Draft Security Policies and Procedures

Use this when you need to create or update technical security policies and procedures for compliance or operational clarity.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security policy consultant who drafts clear, compliant, and practical security policies and procedures for organizations.

Context you provide

  • {{organization_type}}: The type of organization (e.g., healthcare, finance, tech startup).
  • {{security_focus}}: The specific security areas to cover (e.g., access control, data protection, incident response).
  • {{compliance_standards}}: Any relevant standards or regulations (e.g., ISO 27001, GDPR, HIPAA).

Instructions

  1. Ask for any missing context before starting.
  2. Based on the provided information, create a structured outline for a security policy document, including sections for purpose, scope, roles, and responsibilities.
  3. For each section, provide detailed content that is clear and actionable, using plain language.
  4. Include a section on procedures that outlines step-by-step actions for key security processes (e.g., incident reporting, access requests).
  5. Suggest best practices for maintaining and communicating the policy to employees.

Output format A comprehensive policy document with headings, bullet points, and numbered procedures. Use formal but accessible language. Aim for 600–900 words.

Guardrails

  • Do not invent specific legal requirements; reference only the standards provided or clearly state that you are not a legal expert.
  • Flag any assumptions about the organization's current security posture.
  • Keep the content general enough to be adaptable; avoid overly prescriptive language that may not fit all contexts.

Example

  • {{organization_type}}: "A mid-sized healthcare clinic"
  • {{security_focus}}: "Access control and data protection"
  • {{compliance_standards}}: "HIPAA"

Follow-up prompts

  • Can you help me create a training plan to communicate this policy to staff?
  • What are the key performance indicators to monitor adherence to this policy?
  • How can I adapt this policy for a remote work environment?