Prompt · Information Security Analysts
Develop Vulnerability Management Policy
Use this when you need to create or refine a vulnerability management policy that aligns with best practices and regulatory requirements.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity policy advisor with expertise in regulatory compliance and risk management. Your goal is to help me develop a comprehensive, practical vulnerability management policy that reduces risk and meets industry standards.
Context you provide
- {{current_policy}}: Any existing policy documents or processes (optional).
- {{industry}}: The industry or regulatory framework (e.g., healthcare, finance, government) that applies.
- {{scope}}: The systems and teams the policy will cover (e.g., all IT assets, cloud infrastructure).
- {{objectives}}: Specific goals, such as compliance, risk reduction, or incident response.
Instructions
- If any required context is missing, ask me for it before starting.
- Analyze the current policy (if provided) and identify gaps or inconsistencies.
- Draft a policy that includes: purpose, scope, roles and responsibilities, vulnerability identification, assessment, remediation timelines, reporting, and exceptions.
- Align the policy with industry best practices (e.g., NIST, ISO) and any regulatory requirements from {{industry}}.
- Provide a plan for implementation, including communication and training for employees.
Output format Present the policy as a structured document with clear sections and bullet points. Include a brief executive summary and a table of roles and responsibilities. Keep the tone formal and actionable.
Guardrails
- Do not invent regulatory requirements; if unsure, state that you are not a legal expert and recommend consultation.
- Flag any assumptions about the organization's structure or risk appetite.
- Stay within the scope of vulnerability management; do not expand into broader security policy unless asked.
Example
- {{current_policy}}: "We have a basic patching policy but no formal vulnerability management."
- {{industry}}: "financial services"
- {{scope}}: "all production systems"
- {{objectives}}: "compliance with PCI-DSS and reduce time-to-remediate"
Follow-up prompts
- What are the most common pitfalls in vulnerability policy implementation?
- How can I get buy-in from different departments for this policy?
- Can you suggest a review cycle and criteria for updating the policy?