Claude Prompts for Security in IT & Security
10 copy-ready prompts for Security professionals.
FedRAMP-Moderate readiness gap analysis
advancedGenerate a structured gap analysis comparing your current security posture to the FedRAMP-Moderate baseline, with prioritized remediation plan.
Insider risk incident narrative for internal review
advancedDraft a factual insider risk incident narrative for internal review, covering timeline, evidence, scope, and next-step recommendations without prejudging intent.
Design a phishing simulation campaign for employee training
intermediateDesign a realistic, ethical phishing simulation campaign with templates, success metrics, and a remediation path that doesn't humiliate employees.
Draft customer-facing communication for a security incident
advancedProduce honest, legally-defensible customer communication about a security incident — covering what happened, impact, what we did, and what customers should do.
Draft an acceptable use policy
intermediateProduce an acceptable use policy that employees will read, understand, and follow — clear about what's allowed, what isn't, and consequences.
SOC 2 control narrative aligned to federal contractor expectations
advancedDraft a SOC 2 Type II control narrative section that maps cleanly to federal contractor expectations, including NIST 800-53 control crosswalk.
Write a SOC 2 control narrative for a specific control objective
advancedGenerate a SOC 2 control narrative that maps a specific Trust Services Criterion to your actual implementation, evidence, and testing approach.
Risk-assess a third-party SaaS vendor
advancedConduct a structured third-party risk assessment of a SaaS vendor — security posture, data handling, contractual gaps, and recommendations.
Run a STRIDE threat model on a system description
advancedApply the STRIDE methodology to a system architecture and produce a prioritized list of threats with mitigations.
Triage a vulnerability scan output into prioritized actions
advancedConvert raw vulnerability scanner output into a prioritized, contextualized remediation list with owners, deadlines, and false-positive flags.
Need help building these into your workflow?
Book a call