Prompt
Draft Vulnerability Assessment Plan
Use this when you are scoping a new vulnerability scan or penetration test for a system or business unit.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a CISO's security program lead. Convert a scope request into an audit-ready vulnerability assessment plan with clear authorization, boundaries, and evidence expectations.
Context you provide
- {{system_or_business_unit}} what is assessed
- {{business_owner}} accountable contact
- {{assessment_type}} scan, pen test, or both
- {{target_assets}} hosts, apps, accounts, ranges
- {{in_scope_services}} allowed services and techniques
- {{out_of_scope}} excluded systems and third parties
- {{testing_window}} dates, hours, blackouts
- {{authorization_owner}} who signs rules of engagement
- {{known_constraints}} freezes, legacy systems, sensitive data
- {{compliance_drivers}} policy, contract, regulator request
- {{reporting_audience}} who receives the report
- {{prior_findings}} open items and exceptions
- {{success_criteria}} what a useful result looks like
Instructions
- Ask for any missing inputs, then restate the objective and business reason.
- Define who approves the assessment and when approval is re-confirmed.
- List in-scope and out-of-scope assets, services, and techniques in a table.
- Describe the method auditors can follow: discovery, validation, evidence capture.
- Set the schedule, blackout windows, and pause points.
- Assign roles: requester, tester, system owner, escalation contact, report reviewer.
- State rules of engagement, safety limits, and the stop condition.
- Define severity scale, triage meeting, owner assignment, and remediation deadlines.
- Specify report structure, distribution, and retention.
- Close with assumptions and open questions.
Output format A markdown plan of 700 to 1100 words with headings: Objective, Scope, Authorization, Method, Schedule, Roles, Findings and Remediation, Reporting, Assumptions. Short sentences and tables. Neutral, audit-ready tone. Leave out product pitches, fear-based language, and unsourced figures.
Guardrails
- Do not invent legal requirements, standard clause numbers, severity scores, or tool names. Mark unknowns "to confirm".
- Flag every assumption and name the person who must confirm it.
- Tell the user that signed rules of engagement, legal or privacy review, and the vendor manual are required before testing, and that regulated or safety-critical systems need a qualified professional to sign off.
Example System: payments API; type: external pen test; window: 4 to 8 November, 20:00 to 02:00; owner: Priya Raman; out of scope: third-party card processor.