Claude Prompts for IT & Security
Prompts for DevOps, SRE, infosec, and internal IT teams.
26 prompts
Draft an asset management policy
intermediateProduce an asset management policy covering hardware lifecycle, software inventory, ownership, return, and audit cadence.
Write a capacity planning memo with growth assumptions
intermediateProduce a capacity planning memo that turns growth assumptions and current utilization into specific infrastructure asks and risks.
Design a CI/CD pipeline for a new service
advancedProduce a complete CI/CD pipeline design — stages, tools, security gates, environments — for a new service shipping to production.
Document a deployment strategy (blue-green, canary, rolling)
intermediateProduce a written deployment strategy document with rationale, mechanics, rollback procedure, and risk tradeoffs for a specific service.
Review a Dockerfile for security and best practices
intermediateAudit a Dockerfile for security vulnerabilities, image bloat, layer inefficiency, and production-readiness issues.
Generate an IT onboarding checklist for a new hire
beginnerProduce a role-aware IT onboarding checklist covering accounts, hardware, access, training, and day-1/week-1/month-1 milestones.
FedRAMP-Moderate readiness gap analysis
advancedGenerate a structured gap analysis comparing your current security posture to the FedRAMP-Moderate baseline, with prioritized remediation plan.
Triage a helpdesk ticket queue and propose categorization
beginnerConvert a messy helpdesk ticket queue into a categorized, prioritized triage list with assignment recommendations and patterns to address.
Generate an incident response playbook for a service
advancedProduce a service-specific incident response playbook covering severity, roles, comms, common failure modes, and recovery steps.
Draft a status page update during an active incident
intermediateWrite a calm, factual status page update during an active incident that tells customers what is broken, what you know, and when they will hear next, without over-promising.
Insider risk incident narrative for internal review
advancedDraft a factual insider risk incident narrative for internal review, covering timeline, evidence, scope, and next-step recommendations without prejudging intent.
Write a knowledge base article from an FAQ or recurring ticket
beginnerConvert a recurring helpdesk question or ad-hoc FAQ into a clean, scannable knowledge base article that deflects future tickets.
Review a Kubernetes manifest for production readiness
advancedAudit Kubernetes manifests for security context, resource limits, probes, PodSecurity compliance, and HA correctness.
Design a phishing simulation campaign for employee training
intermediateDesign a realistic, ethical phishing simulation campaign with templates, success metrics, and a remediation path that doesn't humiliate employees.
Write a blameless postmortem from incident notes
intermediateConvert raw incident notes into a structured blameless postmortem with timeline, contributing factors, and tracked action items.
Generate a runbook entry from a specific alert
intermediateTurn an alert definition into a complete runbook entry with diagnostics, mitigations, and escalation guidance for the on-call engineer.
Draft a secrets management policy for engineering
intermediateGenerate a practical secrets management policy that engineers will actually follow — covering storage, rotation, access, and incident handling.
Draft customer-facing communication for a security incident
advancedProduce honest, legally-defensible customer communication about a security incident — covering what happened, impact, what we did, and what customers should do.
Draft an acceptable use policy
intermediateProduce an acceptable use policy that employees will read, understand, and follow — clear about what's allowed, what isn't, and consequences.
Write an SLO definition document for a service
advancedProduce a complete SLO definition with SLIs, error budgets, alerting policy, and consequences when the budget is exhausted.
SOC 2 control narrative aligned to federal contractor expectations
advancedDraft a SOC 2 Type II control narrative section that maps cleanly to federal contractor expectations, including NIST 800-53 control crosswalk.
Write a SOC 2 control narrative for a specific control objective
advancedGenerate a SOC 2 control narrative that maps a specific Trust Services Criterion to your actual implementation, evidence, and testing approach.
Review a Terraform module for issues and best practices
advancedAudit a Terraform module for security misconfigurations, drift risk, naming, state hygiene, and reusability issues.
Risk-assess a third-party SaaS vendor
advancedConduct a structured third-party risk assessment of a SaaS vendor — security posture, data handling, contractual gaps, and recommendations.
Run a STRIDE threat model on a system description
advancedApply the STRIDE methodology to a system architecture and produce a prioritized list of threats with mitigations.
Triage a vulnerability scan output into prioritized actions
advancedConvert raw vulnerability scanner output into a prioritized, contextualized remediation list with owners, deadlines, and false-positive flags.
Browse by role
Need help building these into your workflow?
Book a call