Cybersecurity & Risk5.0 · 0 ratings
Zero Trust Architecture Design Advisor
Designs a phased Zero Trust roadmap across identity, device, network, and data pillars with concrete controls.
Role-BasedChain-of-ThoughtStructured-Output
Prompt
ROLE: You are a Zero Trust architect advising an organization transitioning away from a perimeter-based model. CONTEXT: - Current state: [EXISTING_NETWORK_IDENTITY_AND_TOOLING] - Drivers: [REMOTE_WORK_CLOUD_BREACH_COMPLIANCE] - Constraints: [BUDGET_LEGACY_SYSTEMS_TIMELINE] - Crown-jewel assets: [MOST_SENSITIVE_SYSTEMS_DATA] TASK — reason across the pillars (Identity, Devices, Networks, Applications/Workloads, Data) plus Visibility & Automation: 1. Assess current maturity per pillar (Traditional / Initial / Advanced / Optimal) referencing the CISA Zero Trust Maturity Model. 2. Define the 'protect surface' and map transaction flows for the crown-jewel assets. 3. Recommend specific controls per pillar (e.g., phishing-resistant MFA, device posture checks, microsegmentation, least-privilege policies, continuous verification). 4. Sequence the work into Phase 1 (quick wins), Phase 2 (foundational), Phase 3 (optimization), with dependencies. 5. Define success metrics per phase. OUTPUT FORMAT: - Maturity scorecard table (pillar | current | target) - Recommended controls by pillar - Phased roadmap with timelines and dependencies - KPIs to track progress CONSTRAINTS: Be pragmatic about legacy systems — propose compensating controls where full ZT isn't feasible. Avoid vendor lock-in language; describe capabilities, not just products. Quantify the risk reduction rationale for Phase 1 items.
Recommended models
claudegpt-4ogemini
More in Cybersecurity & Risk
STRIDE Threat Model For A New Service
Builds a structured STRIDE threat model for a system with trust boundaries, ranked threats, and concrete mitigations.
Read prompt
Security Incident Postmortem Author
Drafts a blameless post-incident review with timeline, root cause, and corrective actions ready for leadership.
Read prompt
CVE Triage And Prioritization Analyst
Triages a list of CVEs by exploitability and business context to produce an actionable patch priority queue.
Read prompt
Phishing Email Forensic Examiner
Analyzes a suspicious email's headers, URLs, and payload to classify intent and recommend SOC response.
Read prompt