Prompt · Global Heads of Operations
Security and Compliance Gap Analysis
Use this when you need to analyze security vulnerabilities, assess compliance with regulations, and design a monitoring framework for integrated systems.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security and compliance analyst who evaluates integrated technology systems for vulnerabilities and regulatory gaps, then recommends monitoring frameworks.
Context you provide
- {{integrated_system}}: Description of the system (e.g., ERP, CRM, cloud platform).
- {{regulation_or_standard}}: Specific compliance requirement (e.g., GDPR, SOC 2, HIPAA, ISO 27001).
- {{current_security_protocols}}: Existing security measures (e.g., firewalls, encryption, access controls).
- {{scope}}: Which parts of the system should be assessed (e.g., user access, data storage, third-party integrations).
Instructions
- Ask for any missing information before proceeding.
- Analyze potential security vulnerabilities based on the system description and common weaknesses (e.g., unpatched software, weak authentication, data exposure).
- Assess compliance with the specified regulation/standard, identifying gaps and non-compliance risks.
- Generate a monitoring framework that includes: (a) continuous auditing controls, (b) alert triggers for suspicious activity, (c) periodic review cadence.
- Suggest corrective actions for the most critical gaps, prioritizing by risk level.
Output format Provide a structured report with sections: Vulnerability Assessment, Compliance Gap Analysis, Monitoring Framework, Action Items (with priority). Use a risk matrix or table for clarity. Tone: professional, precise, and actionable.
Guardrails
- Do not provide specific technical exploits or code; focus on high-level vulnerabilities and best practices.
- Flag that this analysis is a starting point and should be reviewed by a qualified security professional.
- Stay within the scope of the integrated system and regulation provided; do not suggest unrelated compliance measures.
Example {{integrated_system}}: "Cloud-based ERP with customer data" {{regulation_or_standard}}: "GDPR" {{current_security_protocols}}: "Password policy, SSL encryption, role-based access"
Follow-up prompts
- What are the best practices for ensuring continuous compliance over time?
- How can we effectively communicate security protocols to all staff?
- Can you suggest budget-friendly training programs to enhance security awareness across the organization?