Policy Drafter
Writes complete IS policies from a single prompt. AUP, IR Plan, Access Control, and more.
Generates complete information security policies tailored to your organization size, industry, and target frameworks. Output includes purpose, scope, definitions, policy statements, exceptions process, and review schedule. Ready for leadership sign-off.
Try a sample prompt:
Acceptable Use Policy
Document ID: ACME-POL-AUP-001 · Version: 1.0 · Effective Date: 2026-05-09
Approver: Chief Information Security Officer · Next Review: 2027-05-09
1. Purpose
This policy establishes the rules under which Acme employees, contractors, and authorized third parties may use Acme information systems, networks, and data. It supports Acme's commitments under SOC 2 Type II (CC1.1, CC1.4, CC6.1, CC6.6) and ISO/IEC 27001:2022 (A.5.10, A.6.3, A.8.1).
2. Scope
This policy applies to all personnel with access to Acme systems including full-time employees, part-time staff, contractors, interns, and third-party service providers. It covers all owned, leased, or BYOD endpoints; all SaaS platforms in the corporate identity provider; and all data classified Internal, Confidential, or Restricted per the Data Classification Policy (ACME-POL-DCL-001).
3. Definitions
4. Policy Statements
4.1 Authorized Use
4.2 Authentication and Credentials
4.3 Data Handling
4.4 Endpoint Security
4.5 Network Use
4.6 Email and Communications
5. Roles and Responsibilities
| Role | Responsibility |
| Personnel | Comply with this policy; report violations |
| Manager | Reinforce policy in onboarding and reviews |
| IT | Enforce technical controls; remediate violations |
| Security | Investigate incidents; recommend policy updates |
| CISO | Approve policy revisions; final escalation |
6. Exceptions
Exceptions require written approval from the CISO and shall be documented in the Exception Register (Confluence: Security/Exceptions). Exceptions are valid for a maximum of 12 months and require renewal review.
7. Enforcement
Violations may result in disciplinary action up to and including termination of employment or contract, in accordance with the Employee Handbook §8 and applicable contractor agreements. Suspected criminal activity will be referred to law enforcement.
8. Review and Maintenance
This policy is reviewed annually by the Information Security team and updated as needed. Material changes require CISO approval and re-acknowledgment by all personnel.
9. Related Documents
- ACME-POL-IAM-001 Identity and Access Management Policy
- ACME-POL-DCL-001 Data Classification Policy
- ACME-STD-AI-001 AI Tool Usage Standard
- Employee Handbook §8
10. Document Control
| Version | Date | Author | Description |
| 1.0 | 2026-05-09 | CISO | Initial release |