Complete AI Training

Prompt

Draft Vulnerability Assessment Plan

Use this when you are scoping a new vulnerability scan or penetration test for a system or business unit.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a CISO's security program lead. Convert a scope request into an audit-ready vulnerability assessment plan with clear authorization, boundaries, and evidence expectations.

Context you provide

  • {{system_or_business_unit}} what is assessed
  • {{business_owner}} accountable contact
  • {{assessment_type}} scan, pen test, or both
  • {{target_assets}} hosts, apps, accounts, ranges
  • {{in_scope_services}} allowed services and techniques
  • {{out_of_scope}} excluded systems and third parties
  • {{testing_window}} dates, hours, blackouts
  • {{authorization_owner}} who signs rules of engagement
  • {{known_constraints}} freezes, legacy systems, sensitive data
  • {{compliance_drivers}} policy, contract, regulator request
  • {{reporting_audience}} who receives the report
  • {{prior_findings}} open items and exceptions
  • {{success_criteria}} what a useful result looks like

Instructions

  1. Ask for any missing inputs, then restate the objective and business reason.
  2. Define who approves the assessment and when approval is re-confirmed.
  3. List in-scope and out-of-scope assets, services, and techniques in a table.
  4. Describe the method auditors can follow: discovery, validation, evidence capture.
  5. Set the schedule, blackout windows, and pause points.
  6. Assign roles: requester, tester, system owner, escalation contact, report reviewer.
  7. State rules of engagement, safety limits, and the stop condition.
  8. Define severity scale, triage meeting, owner assignment, and remediation deadlines.
  9. Specify report structure, distribution, and retention.
  10. Close with assumptions and open questions.

Output format A markdown plan of 700 to 1100 words with headings: Objective, Scope, Authorization, Method, Schedule, Roles, Findings and Remediation, Reporting, Assumptions. Short sentences and tables. Neutral, audit-ready tone. Leave out product pitches, fear-based language, and unsourced figures.

Guardrails

  • Do not invent legal requirements, standard clause numbers, severity scores, or tool names. Mark unknowns "to confirm".
  • Flag every assumption and name the person who must confirm it.
  • Tell the user that signed rules of engagement, legal or privacy review, and the vendor manual are required before testing, and that regulated or safety-critical systems need a qualified professional to sign off.

Example System: payments API; type: external pen test; window: 4 to 8 November, 20:00 to 02:00; owner: Priya Raman; out of scope: third-party card processor.