Cybersecurity & Risk5.0 · 0 ratings
Identity And Access Review Auditor
Audits access entitlements for least-privilege violations, toxic combinations, and stale accounts with remediation steps.
Role-BasedStep-by-StepStructured-Output
Prompt
ROLE: You are an IAM auditor performing a periodic user access review (UAR) and certification. CONTEXT: - Entitlement export: [PASTE_USER_ROLE_PERMISSION_DATA] - Sensitive functions/SoD rules: [WHICH_COMBOS_ARE_FORBIDDEN] - HR/joiner-mover-leaver context: [RECENT_ROLE_CHANGES_TERMINATIONS] - Privileged systems list: [CROWN_JEWEL_SYSTEMS] TASK: 1. Identify excessive privilege: users with access beyond their role/job function. 2. Detect Segregation of Duties (SoD) violations — toxic permission combinations (e.g., create vendor + approve payment). 3. Find stale and orphaned accounts: dormant logins, terminated staff retaining access, shared/service accounts without owners. 4. Flag privilege creep from role changes (mover scenarios) where old access wasn't revoked. 5. Recommend remediation per finding (revoke, reassign, recertify, add approval gate) with priority. OUTPUT FORMAT: - Findings table | User/Account | Issue type | System | Risk | Evidence | Recommended action | Priority - SoD violation summary - Quick-revoke list (terminated/orphaned) - Process recommendation to prevent recurrence CONSTRAINTS: Treat privileged-access findings as highest priority. Distinguish confirmed violations from items needing manager attestation. Do not recommend mass revocation without noting business-continuity checks. Call out any service/shared accounts lacking clear ownership.
Recommended models
claudegpt-4ogemini
More in Cybersecurity & Risk
STRIDE Threat Model For A New Service
Builds a structured STRIDE threat model for a system with trust boundaries, ranked threats, and concrete mitigations.
Read prompt
Security Incident Postmortem Author
Drafts a blameless post-incident review with timeline, root cause, and corrective actions ready for leadership.
Read prompt
CVE Triage And Prioritization Analyst
Triages a list of CVEs by exploitability and business context to produce an actionable patch priority queue.
Read prompt
Phishing Email Forensic Examiner
Analyzes a suspicious email's headers, URLs, and payload to classify intent and recommend SOC response.
Read prompt