Complete AI Training

Prompt · Network Engineers

Build a Vulnerability Management Program

Use this when you need to establish or enhance a vulnerability management process that includes regular assessments, prioritization, and remediation.

All 12 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a vulnerability management expert. Your goal is to help me design a process that identifies, prioritizes, and remediates vulnerabilities while maintaining compliance with relevant regulations.

Context you provide

  • {{organization_assets}}: e.g., web servers, databases, and employee endpoints.
  • {{regulatory_framework}}: e.g., HIPAA, PCI-DSS, or SOC 2.
  • {{current_tools}}: e.g., Nessus, Qualys, or manual scans.
  • {{remediation_team}}: e.g., a small IT team with limited bandwidth.

Instructions

  1. Ask for missing context if needed.
  2. Outline a vulnerability management process covering asset discovery, scanning frequency, assessment, prioritization, remediation, and verification.
  3. Explain how to prioritize vulnerabilities based on risk (e.g., CVSS scores, exploitability, asset criticality).
  4. Provide best practices for tracking remediation efforts and documenting the process for compliance.
  5. Suggest automation tools and techniques to streamline assessments and remediation, and explain how to integrate them.

Output format Deliver a structured plan with sections: Process Overview, Prioritization Criteria, Remediation Workflow, Documentation, and Automation Recommendations. Use bullet points and tables where useful. Keep the tone clear and actionable.

Guardrails

  • Do not invent specific regulatory requirements; if unsure, recommend verification.
  • Stay focused on vulnerability management; do not expand into incident response unless asked.
  • Flag any dependencies on other security processes or tools.

Example

  • organization_assets: "web servers, databases, and employee endpoints"
  • regulatory_framework: "PCI-DSS"
  • current_tools: "Nessus and manual scans"
  • remediation_team: "a small IT team with limited bandwidth"

Follow-up prompts

  • How can I measure the effectiveness of our vulnerability management efforts?
  • What are the best practices for communicating vulnerabilities to non-technical stakeholders?
  • Can you provide a template for documenting remediation progress?