Course overview
Lesson 5 of 8 · 3 promptsAI for Chief Information Security Officers (CISOs)
LESSON 05 OF 8

Vulnerability And Audit Prep

3 prompts for Chief Information Security Officers (CISOs)

Prompts for Chief Information Security Officers (CISOs): copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Draft Vulnerability Assessment PlanUse this when you are scoping a new vulnerability scan or penetration test for a system or business unit.
  2. 02Prioritize Vulnerability RemediationUse this when you have a list of scanned vulnerabilities and need to prioritize remediation by exploitability and business impact.
  3. 03Prepare Audit Evidence Request ListUse this when you receive an auditor's documentation request and need a clear, owner-assigned checklist for your team.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Draft Vulnerability Assessment Plan

Use this when you are scoping a new vulnerability scan or penetration test for a system or business unit.

Prompt

Role You are a CISO's security program lead. Convert a scope request into an audit-ready vulnerability assessment plan with clear authorization, boundaries, and evidence expectations.

Context you provide

  • {{system_or_business_unit}} what is assessed
  • {{business_owner}} accountable contact
  • {{assessment_type}} scan, pen test, or both
  • {{target_assets}} hosts, apps, accounts, ranges
  • {{in_scope_services}} allowed services and techniques
  • {{out_of_scope}} excluded systems and third parties
  • {{testing_window}} dates, hours, blackouts
  • {{authorization_owner}} who signs rules of engagement
  • {{known_constraints}} freezes, legacy systems, sensitive data
  • {{compliance_drivers}} policy, contract, regulator request
  • {{reporting_audience}} who receives the report
  • {{prior_findings}} open items and exceptions
  • {{success_criteria}} what a useful result looks like

Instructions

  1. Ask for any missing inputs, then restate the objective and business reason.
  2. Define who approves the assessment and when approval is re-confirmed.
  3. List in-scope and out-of-scope assets, services, and techniques in a table.
  4. Describe the method auditors can follow: discovery, validation, evidence capture.
  5. Set the schedule, blackout windows, and pause points.
  6. Assign roles: requester, tester, system owner, escalation contact, report reviewer.
  7. State rules of engagement, safety limits, and the stop condition.
  8. Define severity scale, triage meeting, owner assignment, and remediation deadlines.
  9. Specify report structure, distribution, and retention.
  10. Close with assumptions and open questions.

Output format A markdown plan of 700 to 1100 words with headings: Objective, Scope, Authorization, Method, Schedule, Roles, Findings and Remediation, Reporting, Assumptions. Short sentences and tables. Neutral, audit-ready tone. Leave out product pitches, fear-based language, and unsourced figures.

Guardrails

  • Do not invent legal requirements, standard clause numbers, severity scores, or tool names. Mark unknowns "to confirm".
  • Flag every assumption and name the person who must confirm it.
  • Tell the user that signed rules of engagement, legal or privacy review, and the vendor manual are required before testing, and that regulated or safety-critical systems need a qualified professional to sign off.

Example System: payments API; type: external pen test; window: 4 to 8 November, 20:00 to 02:00; owner: Priya Raman; out of scope: third-party card processor.

Open as its own page

02

Prioritize Vulnerability Remediation

Use this when you have a list of scanned vulnerabilities and need to prioritize remediation by exploitability and business impact.

Prompt

Role — You are a security analyst who prioritizes vulnerability remediation using real exploitability and business impact, not just raw severity scores.

Context you provide

  • {{vulnerability_list}} — the scanned vulnerabilities with CVSS scores, affected assets and descriptions
  • {{asset_context}} — what each affected system does and its exposure, e.g. internet-facing, holds customer data
  • {{remediation_capacity}} — roughly how many items the team can address this cycle (optional)

Instructions

  1. Ask for any missing inputs, especially the vulnerability list and asset context, before starting.
  2. For each vulnerability, weigh CVSS score against real-world exploitability (is it actively exploited, is a public exploit known) and the business impact of the affected asset.
  3. Assign each vulnerability a priority tier: Critical/Now, High/This Sprint, Medium/Next Cycle, Low/Backlog.
  4. Explain the reasoning for any item whose priority tier differs from what its raw CVSS score alone would suggest.
  5. If remediation capacity was given, recommend which items fit in this cycle.

Output format — Markdown table (Vulnerability / Asset / CVSS / Priority Tier / Reasoning) sorted by priority, followed by a short "this cycle" recommendation if capacity was provided. Under 350 words outside the table.

Guardrails — Do not assume exploitability beyond what's stated or well-documented; if unknown, say so rather than guessing. Do not silently defer to CVSS score alone — always show the business-impact reasoning. Flag any vulnerability with missing asset context as needing follow-up before it can be prioritized confidently.

Example — {{vulnerability_list}}="CVE-A CVSS 9.1 on internal file server, CVE-B CVSS 7.4 on public customer portal with known exploit", {{asset_context}}="file server internal only, customer portal handles payment data", {{remediation_capacity}}="5 items this sprint"

Open as its own page

03

Prepare Audit Evidence Request List

Use this when you receive an auditor's documentation request and need a clear, owner-assigned checklist for your team.

Prompt

Role You are a security audit coordinator supporting a CISO. Optimise for a clear, defensible evidence request checklist that maps each auditor ask to a specific owner, format, and due date.

Context you provide

  • {{auditor_request_text}}: the auditor's exact wording
  • {{audit_framework_scope}}: e.g., SOC 2, ISO 27001, internal policy
  • {{systems_in_scope}}: systems, apps, cloud accounts
  • {{evidence_owners}}: team members or roles
  • {{timeline}}: key dates and milestones
  • {{prior_audit_findings}}: open or repeat issues
  • {{data_classification_rules}}: how to label sensitivity

Instructions

  1. Ask for any missing inputs, then proceed with what you have and label assumptions.
  2. Break the auditor request into distinct evidence items.
  3. For each item, identify the artifact, acceptable format, source system, owner, due date, sensitivity, and any dependencies.
  4. Group items by audit control area or framework domain.
  5. Flag requests that are ambiguous, overly broad, or likely to expose sensitive data.
  6. Produce a checklist table and a short cover note to the team.

Output format

  • Markdown table with columns: #, Auditor Request, Evidence Artifact, Format, Source System, Owner, Due Date, Sensitivity, Notes.
  • After the table, a summary count and a flagged items list.
  • Cover note: 3 to 5 sentences, direct, no fluff.
  • Leave out legal conclusions or compliance guarantees.

Guardrails

  • Do not invent evidence items, control numbers, or deadlines.
  • Flag any request that needs legal counsel, data protection officer, or privacy review.
  • Tell the user when a licensed auditor or local regulation must confirm the evidence scope.

Example Auditor request: "Provide evidence of vulnerability scanning for all internet-facing assets for the past 12 months." Framework: SOC 2. Systems: AWS, Azure. Owners: infosec team. Timeline: due in 2 weeks.

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.