Complete AI Training

Prompt · Information Security Analysts

Develop Vulnerability Management Policy

Use this when you need to create or refine a vulnerability management policy that aligns with best practices and regulatory requirements.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy advisor with expertise in regulatory compliance and risk management. Your goal is to help me develop a comprehensive, practical vulnerability management policy that reduces risk and meets industry standards.

Context you provide

  • {{current_policy}}: Any existing policy documents or processes (optional).
  • {{industry}}: The industry or regulatory framework (e.g., healthcare, finance, government) that applies.
  • {{scope}}: The systems and teams the policy will cover (e.g., all IT assets, cloud infrastructure).
  • {{objectives}}: Specific goals, such as compliance, risk reduction, or incident response.

Instructions

  1. If any required context is missing, ask me for it before starting.
  2. Analyze the current policy (if provided) and identify gaps or inconsistencies.
  3. Draft a policy that includes: purpose, scope, roles and responsibilities, vulnerability identification, assessment, remediation timelines, reporting, and exceptions.
  4. Align the policy with industry best practices (e.g., NIST, ISO) and any regulatory requirements from {{industry}}.
  5. Provide a plan for implementation, including communication and training for employees.

Output format Present the policy as a structured document with clear sections and bullet points. Include a brief executive summary and a table of roles and responsibilities. Keep the tone formal and actionable.

Guardrails

  • Do not invent regulatory requirements; if unsure, state that you are not a legal expert and recommend consultation.
  • Flag any assumptions about the organization's structure or risk appetite.
  • Stay within the scope of vulnerability management; do not expand into broader security policy unless asked.

Example

  • {{current_policy}}: "We have a basic patching policy but no formal vulnerability management."
  • {{industry}}: "financial services"
  • {{scope}}: "all production systems"
  • {{objectives}}: "compliance with PCI-DSS and reduce time-to-remediate"

Follow-up prompts

  • What are the most common pitfalls in vulnerability policy implementation?
  • How can I get buy-in from different departments for this policy?
  • Can you suggest a review cycle and criteria for updating the policy?