Generate a comprehensive security posture assessment that adapts to your infrastructure, maps findings to multiple compliance frameworks, and produces an actionable improvement roadmap.
Act as a senior security consultant conducting a comprehensive security posture assessment. Generate an adaptive assessment framework. ## Configuration - **Organization Type**: [ORG_TYPE e.g. SaaS startup / fintech / healthcare / government / e-commerce] - **Infrastructure**: [INFRA e.g. AWS cloud-native / Azure hybrid / multi-cloud / on-premise] - **Compliance Requirements**: [COMPLIANCE e.g. SOC2+HIPAA / PCI-DSS+SOC2 / ISO27001+GDPR / FedRAMP] - **Assessment Scope**: [SCOPE e.g. full / network-only / application-only / cloud-config] - **Team Resources**: [RESOURCES e.g. 1 security engineer / small team of 3 / dedicated security team of 10+] ## Assessment Framework ### 1. Asset Discovery & Classification - Automated infrastructure enumeration for [INFRA] - Data classification by sensitivity level - Service dependency mapping - External attack surface analysis - Shadow IT discovery techniques ### 2. Control Assessment - Evaluate security controls across 8 domains: - Identity & Access Management - Network Security - Data Protection - Application Security - Endpoint Security - Logging & Monitoring - Incident Response - Business Continuity - Score each domain on 1-5 maturity scale - Map controls to [COMPLIANCE] requirements simultaneously ### 3. Multi-Framework Compliance Mapping - Map each finding to all applicable [COMPLIANCE] controls - Identify overlapping requirements across frameworks - Highlight controls that satisfy multiple standards - Generate per-framework compliance percentage - Identify framework-specific gaps ### 4. Risk-Based Roadmap - Prioritize improvements by risk reduction impact - Scale recommendations to [RESOURCES] capacity - Create 30/60/90/180 day milestones - Estimate budget for each initiative - Define success metrics and KPIs - Include quick wins achievable in first 2 weeks Generate the assessment as a structured report with executive summary, detailed findings, compliance mapping matrices, and the actionable roadmap. Include assessment questionnaires for each domain.
Free to copy and use. Compatible with Claude 4 Opus, GPT-5, Gemini 2.5 Pro, Gemini 2.0 Flash.
Specify your organization type, infrastructure, and all applicable compliance frameworks. Complete the domain questionnaires honestly for accurate assessment. Share the generated roadmap with leadership for buy-in before implementation.
Initial release
Sign in and download this prompt to leave a review.