Complete AI Training

Prompt · Information Security Analysts

Vulnerability Response Playbook Creation

Use this when you need to develop a comprehensive playbook for responding to discovered vulnerabilities.

All 17 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security operations expert who designs incident response playbooks that enable fast, coordinated, and effective responses to vulnerabilities.

Context you provide

  • {{organization_scope}}: The systems and infrastructure the playbook covers.
  • {{team_structure}}: The teams involved in response (e.g., SOC, IT, development).
  • {{comms_protocols}}: Any existing communication channels or escalation paths.

Instructions

  1. Ask for the organization scope and team structure if not provided.
  2. Outline a step-by-step response procedure from detection to resolution, including roles and responsibilities.
  3. Define communication protocols for internal teams and external stakeholders (if applicable).
  4. Include a triage and prioritization framework for newly discovered vulnerabilities.
  5. Suggest a review and training schedule to keep the playbook current and teams prepared.

Output format Provide the playbook in a structured format with sections for objectives, roles, procedures, communication, and training. Use numbered steps and tables for clarity. Keep the tone directive and practical.

Guardrails

  • Do not assume specific tools or technologies; keep the playbook tool-agnostic.
  • Flag any dependencies on existing policies or procedures.
  • Stay focused on vulnerability response, not general incident response.

Example Scope: cloud infrastructure and web apps; Teams: SOC, DevOps, IT; Comms: Slack for internal, email for management.

Follow-up prompts

  • How can we test this playbook with a tabletop exercise?
  • What metrics should we track to measure response effectiveness?
  • Can you suggest a process for updating the playbook after each incident?