AI Agent Hub
Back to skills
🏢

Security Policy Document Generator

Business Operations Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please install @user_2354702d/security-doc-generator according to https://skillhub.cn/install/skillhub.md.

About this skill

Problem

Enterprise security documentation often splits policy, regulation, process, standard, and procedure files across personal folders. Inconsistent numbering, missing cover pages and revision logs, and unclear approval levels make it hard to demonstrate controlled documents during ISMS or MLPS reviews. The described capability standardizes security policy document generation around ISMS frameworks and compliance requirements.

How It Works

The skill organizes output into a five-level document system: level 1 Policy, level 2 Regulation, level 3 Process, level 4 Standard, and level 5 Guideline or Procedure. Each level has a defined scope, content boundary, update cadence, and approval role. For example, access control regulations map to level 2, while firewall configuration standards map to level 4. The generation flow confirms requirements, matches the appropriate template, fills the standard format, revises based on feedback, and archives with a normalized identifier. Document IDs use level code-system code-category code-sequence, such as XXXX-ISMS-POL-001 and XXXX-ISMS-SOP-IR-001, with placeholders like Some Company and XXXX.

Boundaries

It is suited to templated security documents such as information security policy, asset management, access control, change management, incident response, and backup recovery. The material defines structure, numbering, and templates; organization-specific legal clauses, approval chains, and technical parameters still require internal review and cannot substitute for a formal compliance determination.

Use Cases

  • Prepare MLPS or ISMS evidence by turning access control requirements into a level-2 Regulation document with standard numbering and revision records.
  • Draft an information security policy and organizational structure document for a new security team, defining level-1 and level-2 scope, approval roles, and update cycles.
  • Before annual security review, consolidate incident response and change management into a level-3 Process with flow steps, owners, inputs, outputs, and identifiers.
  • Generate level-4 configuration standards and level-5 operational guides before deploying a firewall or database, including configuration rules, command examples, and approvers.

Best For

  • A CISO owning the ISMS document set who needs consistent hierarchy and numbering across policies, regulations, processes, standards, and guides.
  • A security engineer handling MLPS remediation who needs standard-format documents for access control, backup recovery, and related controls.
  • An IT operations owner who needs to convert firewall, endpoint, and database operational requirements into executable level-4 and level-5 documents.
  • A compliance auditor who needs to check document covers, body structure, revision records, and numbering for consistency.