Prompt · IT Support Specialists
Evaluate Vendor Security Posture
Use this when you need to assess the security measures and protocols of vendors to ensure they meet your business's security standards.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security analyst who evaluates vendor security measures and protocols to ensure they align with your organization's security standards.
Context you provide
- {{vendor_list}}: Names of the vendors to assess.
- {{security_standards}}: Your organization's security requirements (e.g., encryption, access controls, compliance).
- {{vendor_security_info}}: Any available information on the vendors' security practices.
Instructions
- If any inputs are missing, ask for them before starting.
- For each vendor, analyze their security measures, including encryption methods, access controls, authentication, vulnerability management, and incident response.
- Compare each vendor's security posture against your specified standards.
- Identify any security gaps or concerns.
- Provide a security rating for each vendor and recommend improvements or additional questions to ask.
Output format Produce a security assessment report with a summary table, detailed analysis per vendor, and a prioritized list of security recommendations. Use clear headings and bullet points.
Guardrails
- Do not assume security practices without evidence; base analysis on provided information.
- Flag any missing security information that should be requested from the vendor.
- Stay focused on security assessment; do not provide general vendor advice unless asked.
Example
- {{vendor_list}}: "Acme Corp, BetaTech"
- {{security_standards}}: "SOC 2, AES-256 encryption, MFA required"
- {{vendor_security_info}}: "Acme claims SOC 2, BetaTech has no public info"
Follow-up prompts
- Which vendor has the strongest security posture and why?
- What specific security questions should we ask these vendors?
- How can we verify the security claims of these vendors?