Fable 5 for security teams is most useful at the drafting stage - where the blank page costs hours. Point it at your scope, your framework, and your industry, and it returns a structured first draft in minutes. Your team still owns every decision; Fable just removes the grunt work of starting from nothing.
Phase 1 - What to gather before you open Fable 5 for security teams
Fable produces better drafts when you give it tight inputs. Spend 20-30 minutes on this phase and you will save far more time in Phase 2.
- Identify the policy you need - acceptable use, password management, incident response, remote access, data classification, or vendor access. One policy at a time.
- Note the compliance framework(s) in scope: ISO 27001, NIST CSF, SOC 2, IT Act 2000, or internal baseline.
- List your industry and any sector-specific obligations (HIPAA for healthcare, RBI guidelines for BFSI, etc.).
- Pull your current version of the policy if one exists - paste it as context so Fable can update rather than start from scratch.
- Write down the intended audience: technical staff, all employees, or executives. Fable adjusts tone and depth when you specify this.
- Note any internal terminology or approved tool names that must appear verbatim (example: your EDR platform name, your ticketing system).
Phase 2 - How to use Fable 5 for security teams to generate the draft
This is where Fable earns its place. Use specific prompts - vague prompts return generic output. The examples below are real patterns that produce usable drafts.
- Start with a scope prompt: 'Draft a remote access policy for a 60-person IT services company in India. Align it to ISO 27001 Annex A.6.7. Audience is all employees. Use plain English.'
- Ask for a section-by-section structure first before generating full text: 'List the headings this policy should include before writing any body content.' Review the outline and remove or add headings before continuing.
- Generate each major section separately so you can review as you go rather than editing a 1,500-word block at the end.
- Use Fable to write the 'Roles and Responsibilities' table - this is where most human-written policies go vague. Prompt: 'Create a responsibilities table for this policy with columns: Role, Responsibility, Review frequency.'
- Ask Fable to flag what is missing: 'What clauses would an ISO 27001 auditor expect to see in this policy that are not in the draft above?' Use the output as a gap checklist.
- Generate two versions of the policy summary: one for technical staff (full detail) and one for all-staff onboarding (plain language, under 300 words).
Phase 3 - Human review before any policy goes live
Fable does not know your actual environment, your real exceptions, or your legal exposure. This phase is non-negotiable. A policy that goes live without human sign-off is a liability, not an asset.
- Read the full draft line by line - do not skim. Look for statements that are technically correct in general but wrong for your environment (example: a password policy that conflicts with your IdP's actual capabilities).
- Check every control reference. If Fable cites ISO 27001 A.8.3 or NIST AC-17, verify the clause exists and that the draft's wording aligns with the actual control text.
- Remove or rewrite any clause that cannot be enforced with your current tools and headcount. Unenforceable policies fail audits and create false confidence.
- Have a second team member review independently - not to fix grammar, but to answer: 'Could a new hire misread any clause in a way that causes a security incident?'
- Route through legal or compliance if the policy covers data retention, employee monitoring, or vendor liability.
- Version, date, and name the owner before publishing. Fable will not do this automatically.
Need help building your policy library?
VITI Security can audit your existing policies, identify gaps against your compliance framework, and work with your team to produce a complete, auditor-ready policy set. Reach out to talk through your requirements.

