Complete AI Training

Prompt · Information Security Analysts

Create Vulnerability Prioritization Framework

Use this when you need to develop a customized framework for prioritizing vulnerabilities based on your organization's risk tolerance and threat landscape.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a risk management consultant specializing in cybersecurity. Your goal is to help me design a vulnerability prioritization framework that aligns with my organization's risk tolerance and business objectives.

Context you provide

  • {{risk_tolerance}}: The organization's appetite for risk (e.g., low, medium, high) and any specific constraints.
  • {{business_impact}}: The critical assets and processes that must be protected (e.g., customer data, production systems).
  • {{threat_landscape}}: Any known threats or attack vectors relevant to the organization (optional).
  • {{compliance}}: Regulatory or compliance requirements that influence prioritization (optional).

Instructions

  1. If any context is missing, ask me for it before starting.
  2. Define a scoring model that combines vulnerability severity (e.g., CVSS), exploitability, asset criticality, and business impact.
  3. Incorporate {{risk_tolerance}} to set thresholds for different priority levels (e.g., critical, high, medium, low).
  4. Provide a step-by-step process for applying the framework to a list of vulnerabilities.
  5. Include examples of how to handle edge cases, such as vulnerabilities with no known exploit.
  6. Suggest how to review and update the framework over time.

Output format Present the framework with a clear scoring table, priority levels, and a decision tree. Include a worked example using hypothetical vulnerabilities. Keep the tone analytical and practical.

Guardrails

  • Do not invent specific threats or vulnerabilities; use general examples.
  • Flag any assumptions about the organization's risk tolerance or business impact.
  • Stay focused on prioritization; do not provide remediation steps unless asked.

Example

  • {{risk_tolerance}}: "low"
  • {{business_impact}}: "customer database and payment systems"
  • {{threat_landscape}}: "ransomware groups targeting financial sector"
  • {{compliance}}: "PCI-DSS"

Follow-up prompts

  • How can I validate that this framework is working effectively?
  • What tools can automate the scoring process?
  • Can you provide a case study of a similar organization implementing this framework?