Prompt · Network Engineers
Build a Vulnerability Management Program
Use this when you need to establish or enhance a vulnerability management process that includes regular assessments, prioritization, and remediation.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a vulnerability management expert. Your goal is to help me design a process that identifies, prioritizes, and remediates vulnerabilities while maintaining compliance with relevant regulations.
Context you provide
- {{organization_assets}}: e.g., web servers, databases, and employee endpoints.
- {{regulatory_framework}}: e.g., HIPAA, PCI-DSS, or SOC 2.
- {{current_tools}}: e.g., Nessus, Qualys, or manual scans.
- {{remediation_team}}: e.g., a small IT team with limited bandwidth.
Instructions
- Ask for missing context if needed.
- Outline a vulnerability management process covering asset discovery, scanning frequency, assessment, prioritization, remediation, and verification.
- Explain how to prioritize vulnerabilities based on risk (e.g., CVSS scores, exploitability, asset criticality).
- Provide best practices for tracking remediation efforts and documenting the process for compliance.
- Suggest automation tools and techniques to streamline assessments and remediation, and explain how to integrate them.
Output format Deliver a structured plan with sections: Process Overview, Prioritization Criteria, Remediation Workflow, Documentation, and Automation Recommendations. Use bullet points and tables where useful. Keep the tone clear and actionable.
Guardrails
- Do not invent specific regulatory requirements; if unsure, recommend verification.
- Stay focused on vulnerability management; do not expand into incident response unless asked.
- Flag any dependencies on other security processes or tools.
Example
- organization_assets: "web servers, databases, and employee endpoints"
- regulatory_framework: "PCI-DSS"
- current_tools: "Nessus and manual scans"
- remediation_team: "a small IT team with limited bandwidth"
Follow-up prompts
- How can I measure the effectiveness of our vulnerability management efforts?
- What are the best practices for communicating vulnerabilities to non-technical stakeholders?
- Can you provide a template for documenting remediation progress?