Prompts for Chief Information Security Officers (CISOs): copy one, fill it in, paste it into your AI.
Track progress as a memberIn this lesson
- 01Draft Vulnerability Assessment PlanUse this when you are scoping a new vulnerability scan or penetration test for a system or business unit.
- 02Prioritize Vulnerability RemediationUse this when you have a list of scanned vulnerabilities and need to prioritize remediation by exploitability and business impact.
- 03Prepare Audit Evidence Request ListUse this when you receive an auditor's documentation request and need a clear, owner-assigned checklist for your team.
Draft Vulnerability Assessment Plan
Use this when you are scoping a new vulnerability scan or penetration test for a system or business unit.
Role You are a CISO's security program lead. Convert a scope request into an audit-ready vulnerability assessment plan with clear authorization, boundaries, and evidence expectations.
Context you provide
- {{system_or_business_unit}} what is assessed
- {{business_owner}} accountable contact
- {{assessment_type}} scan, pen test, or both
- {{target_assets}} hosts, apps, accounts, ranges
- {{in_scope_services}} allowed services and techniques
- {{out_of_scope}} excluded systems and third parties
- {{testing_window}} dates, hours, blackouts
- {{authorization_owner}} who signs rules of engagement
- {{known_constraints}} freezes, legacy systems, sensitive data
- {{compliance_drivers}} policy, contract, regulator request
- {{reporting_audience}} who receives the report
- {{prior_findings}} open items and exceptions
- {{success_criteria}} what a useful result looks like
Instructions
- Ask for any missing inputs, then restate the objective and business reason.
- Define who approves the assessment and when approval is re-confirmed.
- List in-scope and out-of-scope assets, services, and techniques in a table.
- Describe the method auditors can follow: discovery, validation, evidence capture.
- Set the schedule, blackout windows, and pause points.
- Assign roles: requester, tester, system owner, escalation contact, report reviewer.
- State rules of engagement, safety limits, and the stop condition.
- Define severity scale, triage meeting, owner assignment, and remediation deadlines.
- Specify report structure, distribution, and retention.
- Close with assumptions and open questions.
Output format A markdown plan of 700 to 1100 words with headings: Objective, Scope, Authorization, Method, Schedule, Roles, Findings and Remediation, Reporting, Assumptions. Short sentences and tables. Neutral, audit-ready tone. Leave out product pitches, fear-based language, and unsourced figures.
Guardrails
- Do not invent legal requirements, standard clause numbers, severity scores, or tool names. Mark unknowns "to confirm".
- Flag every assumption and name the person who must confirm it.
- Tell the user that signed rules of engagement, legal or privacy review, and the vendor manual are required before testing, and that regulated or safety-critical systems need a qualified professional to sign off.
Example System: payments API; type: external pen test; window: 4 to 8 November, 20:00 to 02:00; owner: Priya Raman; out of scope: third-party card processor.
Prioritize Vulnerability Remediation
Use this when you have a list of scanned vulnerabilities and need to prioritize remediation by exploitability and business impact.
Role — You are a security analyst who prioritizes vulnerability remediation using real exploitability and business impact, not just raw severity scores.
Context you provide
- {{vulnerability_list}} — the scanned vulnerabilities with CVSS scores, affected assets and descriptions
- {{asset_context}} — what each affected system does and its exposure, e.g. internet-facing, holds customer data
- {{remediation_capacity}} — roughly how many items the team can address this cycle (optional)
Instructions
- Ask for any missing inputs, especially the vulnerability list and asset context, before starting.
- For each vulnerability, weigh CVSS score against real-world exploitability (is it actively exploited, is a public exploit known) and the business impact of the affected asset.
- Assign each vulnerability a priority tier: Critical/Now, High/This Sprint, Medium/Next Cycle, Low/Backlog.
- Explain the reasoning for any item whose priority tier differs from what its raw CVSS score alone would suggest.
- If remediation capacity was given, recommend which items fit in this cycle.
Output format — Markdown table (Vulnerability / Asset / CVSS / Priority Tier / Reasoning) sorted by priority, followed by a short "this cycle" recommendation if capacity was provided. Under 350 words outside the table.
Guardrails — Do not assume exploitability beyond what's stated or well-documented; if unknown, say so rather than guessing. Do not silently defer to CVSS score alone — always show the business-impact reasoning. Flag any vulnerability with missing asset context as needing follow-up before it can be prioritized confidently.
Example — {{vulnerability_list}}="CVE-A CVSS 9.1 on internal file server, CVE-B CVSS 7.4 on public customer portal with known exploit", {{asset_context}}="file server internal only, customer portal handles payment data", {{remediation_capacity}}="5 items this sprint"
Prepare Audit Evidence Request List
Use this when you receive an auditor's documentation request and need a clear, owner-assigned checklist for your team.
Role You are a security audit coordinator supporting a CISO. Optimise for a clear, defensible evidence request checklist that maps each auditor ask to a specific owner, format, and due date.
Context you provide
- {{auditor_request_text}}: the auditor's exact wording
- {{audit_framework_scope}}: e.g., SOC 2, ISO 27001, internal policy
- {{systems_in_scope}}: systems, apps, cloud accounts
- {{evidence_owners}}: team members or roles
- {{timeline}}: key dates and milestones
- {{prior_audit_findings}}: open or repeat issues
- {{data_classification_rules}}: how to label sensitivity
Instructions
- Ask for any missing inputs, then proceed with what you have and label assumptions.
- Break the auditor request into distinct evidence items.
- For each item, identify the artifact, acceptable format, source system, owner, due date, sensitivity, and any dependencies.
- Group items by audit control area or framework domain.
- Flag requests that are ambiguous, overly broad, or likely to expose sensitive data.
- Produce a checklist table and a short cover note to the team.
Output format
- Markdown table with columns: #, Auditor Request, Evidence Artifact, Format, Source System, Owner, Due Date, Sensitivity, Notes.
- After the table, a summary count and a flagged items list.
- Cover note: 3 to 5 sentences, direct, no fluff.
- Leave out legal conclusions or compliance guarantees.
Guardrails
- Do not invent evidence items, control numbers, or deadlines.
- Flag any request that needs legal counsel, data protection officer, or privacy review.
- Tell the user when a licensed auditor or local regulation must confirm the evidence scope.
Example Auditor request: "Provide evidence of vulnerability scanning for all internet-facing assets for the past 12 months." Framework: SOC 2. Systems: AWS, Azure. Owners: infosec team. Timeline: due in 2 weeks.
Skills for these tasks
Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.