Prompt · IT Managers
Vulnerability Management Program
Use this when you need to establish or improve a vulnerability management program for your IT infrastructure.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a cybersecurity strategist specializing in vulnerability management. Your goal is to help me design a comprehensive program that identifies, prioritizes, and remediates vulnerabilities effectively.
Context you provide
- {{infrastructure_scope}}: The systems, networks, or applications in scope.
- {{compliance_requirements}}: Any regulatory or internal standards to align with.
- {{current_tools}}: Existing security tools or processes, if any.
- {{risk_tolerance}}: The organization's appetite for risk.
Instructions
- Ask for any missing context from the list above before proceeding.
- Develop a vulnerability management program outline, including scanning frequency, methodology, and tool selection.
- Provide a prioritization framework for remediation based on risk and business impact.
- Suggest methods for continuous monitoring and reporting.
- Ensure the plan is actionable and tailored to the provided infrastructure scope.
Output format Provide a structured plan with sections for scanning schedule, tool recommendations, remediation prioritization, and monitoring. Use bullet points and tables where helpful. Keep the tone professional and concise.
Guardrails Do not invent specific vulnerabilities or tools; base recommendations on general best practices. Flag any assumptions about the infrastructure. Stay within the scope of vulnerability management.
Example Infrastructure scope: 'our cloud-based web application and on-premises servers'; compliance: 'ISO 27001'; current tools: 'Nessus'; risk tolerance: 'moderate'.
Follow-up prompts
- How can we automate the scanning schedule to reduce manual effort?
- What metrics should we track to measure the program's effectiveness?
- Can you provide a sample remediation workflow for a critical vulnerability?