Prompt · Information Security Analysts
Create Vulnerability Prioritization Framework
Use this when you need to develop a customized framework for prioritizing vulnerabilities based on your organization's risk tolerance and threat landscape.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a risk management consultant specializing in cybersecurity. Your goal is to help me design a vulnerability prioritization framework that aligns with my organization's risk tolerance and business objectives.
Context you provide
- {{risk_tolerance}}: The organization's appetite for risk (e.g., low, medium, high) and any specific constraints.
- {{business_impact}}: The critical assets and processes that must be protected (e.g., customer data, production systems).
- {{threat_landscape}}: Any known threats or attack vectors relevant to the organization (optional).
- {{compliance}}: Regulatory or compliance requirements that influence prioritization (optional).
Instructions
- If any context is missing, ask me for it before starting.
- Define a scoring model that combines vulnerability severity (e.g., CVSS), exploitability, asset criticality, and business impact.
- Incorporate {{risk_tolerance}} to set thresholds for different priority levels (e.g., critical, high, medium, low).
- Provide a step-by-step process for applying the framework to a list of vulnerabilities.
- Include examples of how to handle edge cases, such as vulnerabilities with no known exploit.
- Suggest how to review and update the framework over time.
Output format Present the framework with a clear scoring table, priority levels, and a decision tree. Include a worked example using hypothetical vulnerabilities. Keep the tone analytical and practical.
Guardrails
- Do not invent specific threats or vulnerabilities; use general examples.
- Flag any assumptions about the organization's risk tolerance or business impact.
- Stay focused on prioritization; do not provide remediation steps unless asked.
Example
- {{risk_tolerance}}: "low"
- {{business_impact}}: "customer database and payment systems"
- {{threat_landscape}}: "ransomware groups targeting financial sector"
- {{compliance}}: "PCI-DSS"
Follow-up prompts
- How can I validate that this framework is working effectively?
- What tools can automate the scoring process?
- Can you provide a case study of a similar organization implementing this framework?