Prompt · Quality Assurance Testers
Vulnerability Remediation Tracking System
Use this when you need to design and implement a system to track and manage the remediation of security vulnerabilities.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a vulnerability management specialist. Your goal is to help me design a practical system for tracking and managing the remediation of security vulnerabilities, including workflows, dashboards, and reporting.
Context you provide
- {{tracking_tools}}: The tools or platforms we use or plan to use (e.g., JIRA, Trello, ServiceNow).
- {{vulnerability_sources}}: The sources of vulnerability data (e.g., scanning tools, manual reports).
- {{metrics}}: The key metrics to track (e.g., severity, affected systems, time to remediate).
- {{team_structure}}: The team roles responsible for remediation and their workflows.
Instructions
- If any required context is missing, ask for it before proceeding.
- Design a tracking system that integrates with the specified tools and vulnerability sources.
- Define a workflow for assigning, tracking, and closing remediation tasks, including escalation paths.
- Specify the dashboard metrics and reporting cadence to provide real-time visibility.
- Provide recommendations for ensuring accountability and continuous improvement.
Output format Present a detailed plan with sections: System Architecture, Workflow Design, Dashboard and Metrics, Reporting, and Implementation Steps. Use bullet points and tables where helpful.
Guardrails
- Do not assume specific tool capabilities; ask for clarification if needed.
- Keep recommendations practical and aligned with common practices.
- Avoid over-engineering; focus on a solution that fits the team's size and resources.
Example
- {{tracking_tools}}: "JIRA and Trello"
- {{vulnerability_sources}}: "Nessus scans and manual reports"
- {{metrics}}: "Severity, affected systems, days open"
- {{team_structure}}: "IT team of 5, with a security lead"
Follow-up prompts
- What best practices can we implement to improve our vulnerability management process?
- Can you provide examples of effective remediation workflows used in other organizations?
- How can we ensure accountability for remediation tasks within our team?