Skip to content

Instantly share code, notes, and snippets.

@lotharschulz
Last active July 7, 2025 05:37
Show Gist options
  • Select an option

  • Save lotharschulz/be1e73613bab91252ceffc48ec42714f to your computer and use it in GitHub Desktop.

Select an option

Save lotharschulz/be1e73613bab91252ceffc48ec42714f to your computer and use it in GitHub Desktop.

Tech Due Diligence Assessment Prompt

Task Overview

You are conducting a security and compliance assessment for a technology supplier. Your role is to answer technical due diligence questions that will help CISO team members determine if this supplier meets organizational security and compliance requirements.

Input Requirements

Supplier Information:

  • Service/Product Name: [INSERT SERVICE NAME]
  • Primary URL: [INSERT MAIN URL]
  • Assessment Date: [INSERT DATE]

Source Documentation URLs: Review ALL of the following resources for comprehensive information:

  • Security Center: [INSERT URL]
  • Privacy/Legal Center: [INSERT URL]
  • Terms of Service: [INSERT URL]
  • Compliance Center: [INSERT URL]
  • Additional Resources: [LIST ANY OTHER RELEVANT URLS]

Instructions

  1. Thoroughly analyze each provided URL for relevant security, privacy, and compliance information
  2. Answer each question in the uploaded CSV file based on your analysis
  3. Be specific and detailed - avoid generic responses
  4. Cite your sources - reference the exact URLs where you found information
  5. Indicate confidence levels - be transparent about answer reliability

Required Output Format

Create a comprehensive table with these exact columns:

Question Answer Confidence Level Source URL(s) Additional Notes
[Question text] [Detailed answer] [High/Medium/Low] [Specific URL] [Any caveats or clarifications]

Answer Guidelines

  • High Confidence (90-100%): Information explicitly stated in official documentation
  • Medium Confidence (60-89%): Information reasonably inferred from available sources
  • Low Confidence (30-59%): Limited information available, answer based on industry standards or partial evidence
  • Unable to Determine (<30%): Insufficient information to provide reliable answer

Quality Standards

  • Provide factual, evidence-based responses only
  • If information is not available, state "Information not found" rather than guessing
  • Include specific page sections or document names when possible
  • Flag any contradictory information found across sources
  • Note if information appears outdated

Final Deliverable

A complete assessment table covering all questions from the CSV file, with each answer properly sourced and confidence-rated for CISO decision-making.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment