Helpful AI assistant prompts
We’ve generated a non-exhaustive list of helpful prompts you can use with Aurora. Give them a shot!
Compliance posture
- “Show my compliance summary.”
- “Which control families have the lowest compliance rates?”
- “List all Not Met controls.”
- “Show Not Met Access Control controls.”
- “What is my DAM score?”
- “Show the implementation details for control 3.1.1.”
Remediation
- “Show high risks.”
- “List POA&M items due soon.”
- “Which assets contain CUI?”
- “Show risks for [asset name].”
- “What controls are Not Met in Incident Response?”
- “What is preventing us from reaching compliance?”
Evidence and audit activity
- “Show recent audit activity.”
- “List our asset inventory.”
- “Show our CUI inventory.”
- “Find controls related to MFA.”
- “Find controls related to incident response testing.”
Framework guidance
- “Which clauses should I expect to find in my contract that pertain to CMMC?”
- “What does CMMC Level 2 require for access control?”
- “Explain CMMC requirements for audit logging.”
- “What is the current CMMC Level 2 baseline?”
- “What assessment objectives apply to [CMMC control]?”
- “Explain the difference between CMMC Level 2 and NIST SP 800-171 Rev. 3.”
- “What is the defined Organization-Defined Parameter (ODP) for session timeouts?”
Your work
- “What are my tasks?”
- “What is assigned to me?”
- “What is overdue for me?”
Updates
- “Mark AC.L2-3.1.1 as Met.”
- “Mark all Not Met Incident Response controls as Trending Met.”
- “Set the details for control 3.1.1 to: [text].”
- “Update all Access Control controls currently Not Met to Met.”
- “Add this comment to control 3.1.5: [text].”
- “Change the shared responsibility text for [control ID] to: [text].”
- “Undo the last change.”
- For your current posture, especially useful prompts are:
- “Show the Not Met Incident Response controls.”
- “List non-compliant System & Information Integrity controls.”
- “Show the <four> Not Met Access Control controls.”
- “Show the <two> Not Met Identification & Authentication controls.”
Configuration management
- “We are planning on making the following change to our covered system: <describe change>. Please perform a security impact analysis (SIA) for this change, taking into account our current SSP and risks. Please include the following in the SIA results: High-level risk assessment (High, Moderate, Low), detailed risk assessment with suggesting mitigations, a list of affected 800-171 security controls, what changes we will need to make to the implementation details for those controls, and a suggested go / no-go decision based on the SIA results.”
- “Who should authorize a change to our system?”
Risk management
- “Please perform a qualitative risk assessment for <describe relevant asset type> when faced with <describe target threat event>. Using the current SSP, display the existing Avertive, Preventive, Detective, and Corrective controls, and suggest necessary corrective action plans to mitigate the residual risk.”
