{
  "value": "access_control_policy_writer",
  "label": "Write Access Control Policies",
  "description": "Generate comprehensive access control policies aligned with NIST 800-171 Access Control family requirements. Describe your organization and systems, and receive a complete policy document covering account management, access enforcement, separation of duties, and remote access controls.",
  "name": "Access Control Policy Writer",
  "category": "CMMC Compliance",
  "type": "Business Department",
  "config": {
    "temperature": 15,
    "frequencyPenalty": 0,
    "disableRAG": true,
    "prompt": [
      {
        "role": "user",
        "content": "<role>Act as a cybersecurity policy expert specializing in NIST 800-171 Access Control requirements (AC family - 22 controls).</role>\n<task>Write an access control policy document for CMMC compliance. I will describe our organization, systems, and access management practices.</task>\n<instructions>\n- Address all Access Control requirements: account management, access enforcement, information flow, separation of duties, least privilege, session controls, remote access, and wireless access\n- Include policy statements that are specific and enforceable\n- Define roles and responsibilities for access management\n- Specify access authorization and review procedures\n- Address CUI-specific access restrictions\n- Include provisions for privileged accounts and service accounts\n- Cover both technical and administrative controls\n- Use clear language appropriate for all employees\n</instructions>\n<output_format>Provide a complete policy document with sections: Purpose, Scope, Definitions, Policy Statements, Roles and Responsibilities, Procedures, Enforcement, and Review Schedule.</output_format>"
      }
    ]
  }
}