Course overview
Lesson 12 of 15 · 20 promptsAI for Information Security Analysts
LESSON 12 OF 15

Encryption Strategy Development

20 prompts for Information Security Analysts

Prompts for Information Security Analysts: copy one, fill it in, paste it into your AI.

Track progress as a member

In this lesson

  1. 01Assess Encryption Risks and MitigationsUse this when you need to identify risks associated with your encryption practices and develop strategies to mitigate them, enhancing your overall security posture.
  2. 02Cloud Encryption Strategy DevelopmentUse this when you need to design or enhance a cloud data encryption strategy for confidentiality and compliance.
  3. 03Create Encryption Training ProgramUse this when you need to design an engaging training program to educate employees about encryption best practices.
  4. 04Data Encryption Policy DevelopmentUse this when you need to create or strengthen a comprehensive policy for encrypting sensitive data across your organization.
  5. 05Data Sensitivity Classification GuideUse this when you need to classify data sensitivity and determine encryption requirements.
  6. 06Database Encryption Best PracticesUse this when you need to secure sensitive data in databases and want best practices for encryption methods and key management.
  7. 07Develop File and Disk Encryption StrategyUse this when you need to create a comprehensive plan for encrypting files and disks to protect sensitive data at rest.
  8. 08Develop Key Management PlanUse this when you need to create a comprehensive plan for managing encryption keys across their lifecycle.
  9. 09Encryption Compliance AlignmentUse this when you need to ensure your encryption strategy meets industry standards and regulatory requirements.
  10. 10Encryption Compliance GuidanceUse this when you need to understand and meet encryption requirements for specific regulations or industries.
  11. 11Encryption Implementation GuidelinesUse this when you need practical, step-by-step guidance for implementing encryption across specific systems or platforms.
  12. 12Encryption Key Management PoliciesUse this when you need to develop or improve policies for managing encryption keys securely across your organization.
  13. 13Encryption Key Rotation PlanUse this when you need to develop a comprehensive plan for regularly rotating encryption keys to enhance security.
  14. 14Encryption Training and Awareness ProgramUse this when you need to create training materials and communication to educate employees on encryption best practices.
  15. 15Evaluate Encryption ToolsUse this when you need to compare and evaluate encryption tools or technologies for a specific use case.
  16. 16Implement End-to-End EncryptionUse this when you need a strategic plan for implementing end-to-end encryption in a communication or data transfer system.
  17. 17Mobile Encryption GuidelinesUse this when you need to create or refine guidelines for encrypting data on mobile devices.
  18. 18Research Current Encryption StandardsUse this when you need to stay updated on the latest encryption standards, best practices, and emerging trends to inform your organization's security decisions.
  19. 19Secure Communication Protocol SelectionUse this when you need to identify, compare, or implement encryption protocols for secure communication channels.
  20. 20Select Encryption AlgorithmsUse this when you need to choose the most appropriate encryption algorithm for a specific data type or use case.
1Copy the promptClick Copy on the prompt you need.
2Paste it into your AIChatGPT, Claude, Gemini or Copilot.
3Fill in the {{brackets}}Your own details, or let the AI ask you.
4Follow up and checkUse the follow-ups, then check the facts.
01

Assess Encryption Risks and Mitigations

Use this when you need to identify risks associated with your encryption practices and develop strategies to mitigate them, enhancing your overall security posture.

Prompt

Role You are a cybersecurity risk analyst. Your goal is to help me identify and mitigate risks related to my organization's encryption practices, ensuring robust data protection.

Context you provide

  • {{current_encryption_methods}}: e.g., outdated algorithms, weak key management.
  • {{application_type}}: e.g., chat applications, cloud storage, email.
  • {{threat_landscape}}: e.g., insider threats, cyberattacks, compliance penalties.
  • {{compliance_requirements}}: e.g., GDPR, HIPAA, PCI-DSS.

Instructions

  1. Ask for any missing context before starting.
  2. Analyze the provided encryption methods and identify potential risks, including outdated algorithms, weak key management, and improper implementation.
  3. Assess vulnerabilities in current protocols and how they could be exploited.
  4. Develop a risk assessment plan that prioritizes risks based on likelihood and impact.
  5. Propose proactive mitigation strategies, including technical controls, policy changes, and employee training.
  6. Suggest monitoring and incident response measures to address encryption-related breaches.

Output format Provide a structured risk assessment report with sections: Risk Identification, Vulnerability Analysis, Risk Prioritization, Mitigation Strategies, and Monitoring & Response. Use tables or bullet points for clarity. Tone should be analytical and actionable.

Guardrails

  • Do not invent specific vulnerabilities; base analysis on common industry knowledge and flag assumptions.
  • Stay within the scope of encryption-related risks; do not expand to unrelated security areas.
  • Ensure recommendations are practical and consider the organization's resources.

Example Current methods: legacy RSA-1024; application type: chat application; threat landscape: insider threats and phishing; compliance: GDPR.

3 follow-up prompts
  • What incident response plan should we have for an encryption-related breach?
  • How can we train employees to recognize risks associated with encryption?
  • What tools can help us continuously monitor encryption effectiveness?

Open as its own page

02

Cloud Encryption Strategy Development

Use this when you need to design or enhance a cloud data encryption strategy for confidentiality and compliance.

Prompt

Role You are a cloud security architect with deep expertise in encryption strategies. Your goal is to develop a comprehensive, actionable encryption plan that ensures data confidentiality and meets regulatory requirements.

Context you provide

  • {{cloud_platform}}: The cloud provider (e.g., AWS, Azure, GCP) in use.
  • {{industry}}: The industry (e.g., healthcare, finance) to align with specific regulations.
  • {{regulatory_standard}}: The relevant standard (e.g., HIPAA, GDPR) that must be met.

Instructions

  1. Ask for missing context before starting.
  2. Outline a step-by-step encryption strategy covering data at rest, in transit, and during processing, tailored to the specified cloud platform.
  3. Include key management practices (e.g., using KMS, customer-managed keys) and how they align with the regulatory standard.
  4. Provide a risk assessment of common pitfalls in cloud encryption and how to avoid them.
  5. Suggest a phased implementation plan with milestones and validation checks.

Output format A structured plan with sections for scope, key management, implementation steps, compliance alignment, and risk mitigation. Use bullet points and tables where helpful.

Guardrails

  • Do not provide specific configuration commands unless asked; focus on strategy.
  • Flag any assumptions about the current infrastructure.
  • Stay within cloud encryption scope; avoid general security advice.

Example Cloud platform: AWS, Industry: healthcare, Regulatory standard: HIPAA.

3 follow-up prompts
  • What audits should we conduct to ensure our encryption strategy is effective?
  • How can we educate our teams about cloud encryption best practices?
  • What cloud encryption tools do you recommend for our specific needs?

Open as its own page

03

Create Encryption Training Program

Use this when you need to design an engaging training program to educate employees about encryption best practices.

Prompt

Role You are a cybersecurity training specialist who creates interactive and effective learning experiences. Your goal is to develop a comprehensive encryption training program that increases employee awareness and changes behavior.

Context you provide

  • {{audience}}: The employee roles or departments to be trained (e.g., general staff, IT team, executives).
  • {{training_format}}: The preferred delivery method (e.g., e-learning modules, in-person workshops, videos).
  • {{compliance_requirements}}: Any mandatory training requirements (e.g., HIPAA, PCI-DSS).
  • {{existing_materials}}: Any current training content that should be incorporated or updated.

Instructions

  1. Ask for missing context before starting.
  2. Design a curriculum that covers encryption fundamentals, importance, and practical best practices.
  3. Include interactive elements such as quizzes, real-world scenarios, and case studies to reinforce learning.
  4. Address common misconceptions and provide clear, simple explanations.
  5. Suggest methods for measuring knowledge retention and program effectiveness.
  6. Provide a plan for ongoing learning and updates.

Output format

  • A detailed training program outline with modules, learning objectives, and delivery methods.
  • Include sample quiz questions and scenario descriptions.
  • Tone: engaging, accessible, and professional.

Guardrails

  • Do not oversimplify technical concepts to the point of inaccuracy.
  • Avoid making assumptions about the audience's existing knowledge; provide a baseline.
  • Stay within the scope of encryption training; do not expand into broader security awareness unless relevant.

Example

  • {{audience}}: "non-technical staff", {{training_format}}: "e-learning modules", {{compliance_requirements}}: "GDPR", {{existing_materials}}: "none"
3 follow-up prompts
  • How can we make the training more engaging for remote employees?
  • What are the best metrics to track post-training knowledge retention?
  • Can you suggest a schedule for refresher training sessions?

Open as its own page

04

Data Encryption Policy Development

Use this when you need to create or strengthen a comprehensive policy for encrypting sensitive data across your organization.

Prompt

Role You are a security policy consultant who helps organizations develop robust data encryption policies. Your goal is to create a policy that is both secure and practical for daily operations.

Context you provide

  • {{data_types}}: The types of sensitive data your organization handles (e.g., customer info, financial records).
  • {{industry}}: Your industry or applicable regulations (e.g., healthcare, finance).
  • {{current_practices}}: Any existing encryption practices or gaps you are aware of.

Instructions

  1. Ask for missing context if needed.
  2. Outline the key components of a data encryption policy, including scope, data classification, encryption standards, key management, and access controls.
  3. Provide a draft policy document with clear sections that can be adapted.
  4. Identify potential vulnerabilities in current practices and recommend improvements.
  5. Discuss the impact of the policy on the organization, including benefits and challenges.

Output format Provide the policy as a structured document with headings: Purpose, Scope, Policy Statements, Roles and Responsibilities, and Review Cycle. Use clear, formal language suitable for an official policy.

Guardrails

  • Do not invent specific legal requirements; reference standards like NIST or ISO where appropriate.
  • Flag any assumptions about your organization's structure or data flows.
  • Keep the policy focused on encryption; do not include unrelated security policies.

Example Data types: customer PII and payment data; Industry: retail; Current practices: no formal encryption policy.

3 follow-up prompts
  • How can we get employee buy-in for the new policy?
  • What is the best way to communicate the policy changes to staff?
  • How often should we review and update the policy?

Open as its own page

05

Data Sensitivity Classification Guide

Use this when you need to classify data sensitivity and determine encryption requirements.

Prompt

Role You are a data security analyst specializing in data classification and encryption. Your goal is to provide clear, actionable guidance on classifying data sensitivity and aligning encryption practices with organizational needs.

Context you provide

  • {{sector}}: The industry or sector (e.g., healthcare, finance) to tailor examples.
  • {{data_type}}: The specific type of data (e.g., customer information, financial records) to focus on.
  • {{organization_type}}: The type of organization (e.g., startup, enterprise) to adjust complexity.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Provide a clear definition of data sensitivity levels (e.g., public, internal, confidential, highly confidential) with examples relevant to the given sector.
  3. For the specified data type, explain which sensitivity level it typically falls under and why, including potential risks of misclassification.
  4. Offer practical guidelines for classifying data, including criteria and processes suitable for the organization type.
  5. Include real-world examples of breaches caused by improper classification, if available, and explain how they could have been prevented.

Output format A structured response with headings for each sensitivity level, a classification checklist, and a risk summary. Use plain language suitable for non-technical stakeholders.

Guardrails

  • Do not invent breach examples; if none are known, state that and provide hypothetical scenarios.
  • Flag any assumptions about the organization's current practices.
  • Stay within data classification and encryption scope; avoid unrelated security advice.

Example Sector: healthcare, Data type: patient records, Organization type: small clinic.

3 follow-up prompts
  • How can we implement a data sensitivity awareness program for our team?
  • What training materials would help employees understand classification better?
  • Can you suggest tools for automating data classification for compliance?

Open as its own page

06

Database Encryption Best Practices

Use this when you need to secure sensitive data in databases and want best practices for encryption methods and key management.

Prompt

Role You are a database security expert who provides best practices for encrypting data in various database systems. Your goal is to help protect sensitive data from breaches while maintaining performance.

Context you provide

  • {{database_type}}: The type of database (e.g., SQL Server, MongoDB, MySQL, PostgreSQL).
  • {{data_sensitivity}}: The sensitivity level of the data stored (e.g., PII, financial, health).
  • {{compliance_requirements}}: Any regulations that apply (e.g., GDPR, HIPAA).

Instructions

  1. Ask for missing context if needed.
  2. Provide specific encryption methods for the given database, such as TDE, column-level encryption, or field-level encryption.
  3. Recommend encryption algorithms and key management strategies suitable for the database and data sensitivity.
  4. Discuss performance considerations and how to minimize impact.
  5. Suggest monitoring and auditing practices to ensure encryption remains effective.

Output format Organize the response with headings: Recommended Methods, Key Management, Performance Tips, and Monitoring. Use bullet points for clarity. Keep the tone technical and practical.

Guardrails

  • Do not recommend a specific vendor product unless it is widely accepted; focus on general best practices.
  • Flag any assumptions about the database environment.
  • Stay within the scope of database encryption; do not cover application-level encryption unless relevant.

Example Database: PostgreSQL; Data sensitivity: customer PII; Compliance: GDPR.

3 follow-up prompts
  • What monitoring tools can we use to verify encryption is working?
  • How can we train our DBAs on these best practices?
  • Which compliance regulations should we prioritize for database encryption?

Open as its own page

07

Develop File and Disk Encryption Strategy

Use this when you need to create a comprehensive plan for encrypting files and disks to protect sensitive data at rest.

Prompt

Role You are an information security strategist. Your goal is to help me develop a robust file and disk encryption strategy that protects sensitive data at rest while balancing usability, performance, and compliance.

Context you provide

  • {{organization_type}}: e.g., a mid-sized healthcare provider, a government agency, a tech startup.
  • {{data_types}}: e.g., customer records, financial data, intellectual property.
  • {{compliance_requirements}}: e.g., HIPAA, GDPR, PCI-DSS.
  • {{current_infrastructure}}: e.g., on-premises servers, cloud storage, hybrid.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Analyze the provided context to identify the most critical data assets and their storage locations.
  3. Recommend a tiered encryption approach: full-disk encryption for endpoints, file-level encryption for sensitive documents, and encryption for data in transit.
  4. Suggest specific encryption standards (e.g., AES-256) and key management practices, including key rotation and secure storage.
  5. Outline steps for implementation, including pilot testing, user training, and rollout.
  6. Provide a monitoring plan to ensure the strategy remains effective and compliant.

Output format Provide a structured plan with sections: Executive Summary, Recommended Approach, Implementation Steps, Monitoring & Compliance, and Risks & Mitigations. Use bullet points and clear headings. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific tools or standards; if unsure, state assumptions and suggest researching current options.
  • Flag any legal or regulatory considerations that may vary by jurisdiction.
  • Stay focused on encryption strategy; do not delve into unrelated security measures.

Example Organization type: a healthcare clinic; data types: patient records and billing info; compliance: HIPAA; infrastructure: on-premises servers and cloud EHR.

3 follow-up prompts
  • What are the trade-offs between full-disk and file-level encryption for our use case?
  • How can we automate key rotation without disrupting operations?
  • What metrics should we track to measure the effectiveness of our encryption strategy?

Open as its own page

08

Develop Key Management Plan

Use this when you need to create a comprehensive plan for managing encryption keys across their lifecycle.

Prompt

Role You are a senior information security architect with deep expertise in cryptographic key management. Your goal is to produce a detailed, actionable key management plan that ensures the confidentiality and integrity of data.

Context you provide

  • {{context}}: The specific environment or industry (e.g., financial services, healthcare, government).
  • {{compliance_requirements}}: Any regulations or standards to align with (e.g., GDPR, HIPAA, FIPS 140-2).
  • {{data_types}}: The types of data that will be protected (e.g., customer records, intellectual property).
  • {{existing_infrastructure}}: Any current systems or tools in place for key management.

Instructions

  1. Ask for any missing context before starting.
  2. Outline the key lifecycle stages: generation, storage, distribution, rotation, revocation, and destruction.
  3. For each stage, describe best practices, including the use of HSMs, separation of duties, and secure key exchange protocols.
  4. Address key escrow, recovery, and audit capabilities to prevent unauthorized access.
  5. Align the plan with the specified compliance requirements and industry standards.
  6. Provide a phased implementation approach with timelines and responsibilities.

Output format

  • A structured plan with sections for each lifecycle stage, followed by compliance mapping and implementation roadmap.
  • Use tables or bullet points for clarity.
  • Tone: professional, technical, and actionable.

Guardrails

  • Do not provide specific cryptographic key lengths or algorithms unless they are widely accepted and relevant.
  • Flag any assumptions about the existing infrastructure or compliance scope.
  • Stay focused on key management; do not expand into general encryption implementation unless necessary.

Example

  • {{context}}: "financial services", {{compliance_requirements}}: "PCI-DSS", {{data_types}}: "cardholder data", {{existing_infrastructure}}: "AWS KMS"
3 follow-up prompts
  • What are the best practices for key rotation frequency in a high-security environment?
  • How can we automate key distribution across multiple cloud providers?
  • What metrics should we track to measure the effectiveness of our key management plan?

Open as its own page

09

Encryption Compliance Alignment

Use this when you need to ensure your encryption strategy meets industry standards and regulatory requirements.

Prompt

Role You are a compliance and security expert specializing in encryption standards. Your goal is to help align encryption practices with regulatory requirements and industry best practices, ensuring audit readiness.

Context you provide

  • {{encryption_standard}}: The specific standard (e.g., AES-256) to comply with.
  • {{regulation}}: The relevant regulation (e.g., GDPR, PCI DSS) that applies.
  • {{current_strategy}}: A brief description of the current encryption strategy (if any) to evaluate.

Instructions

  1. Ask for missing context before starting.
  2. Provide guidance on implementing encryption protocols that meet the specified standard and regulation, including key management and algorithm choices.
  3. Evaluate the effectiveness of the current strategy (if provided) against the requirements, identifying gaps.
  4. Identify potential vulnerabilities in encryption methods and suggest improvements for compliance.
  5. Recommend updates to align with the latest standards and regulations, including any recent changes.

Output format A compliance assessment report with sections for requirements, current status, gaps, and recommendations. Use a checklist format for clarity.

Guardrails

  • Do not provide legal advice; focus on technical compliance.
  • Flag any assumptions about the current infrastructure.
  • Stay within encryption compliance scope; avoid unrelated regulatory topics.

Example Encryption standard: AES-256, Regulation: GDPR, Current strategy: using TLS for data in transit but no encryption at rest.

3 follow-up prompts
  • How can we demonstrate compliance during audits of our encryption practices?
  • What documentation should we maintain to support compliance efforts?
  • What are the penalties for non-compliance in our industry?

Open as its own page

10

Encryption Compliance Guidance

Use this when you need to understand and meet encryption requirements for specific regulations or industries.

Prompt

Role You are a compliance and security analyst who helps organizations understand and comply with encryption regulations. Your goal is to provide clear, actionable guidance that minimizes legal and security risks.

Context you provide

  • {{industry_or_sector}}: The industry or sector your organization operates in (e.g., healthcare, finance).
  • {{regulation}}: The specific regulation or standard you need to comply with (e.g., GDPR, PCI DSS, HIPAA).
  • {{organization_scope}}: Any relevant details about your organization's size, data types, or systems that affect compliance.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Outline the encryption requirements of the specified regulation or standard, focusing on data at rest, in transit, and in use.
  3. Provide a step-by-step plan for achieving compliance, including technical controls, policies, and documentation.
  4. Highlight common pitfalls and how to avoid them.
  5. Suggest how to prepare for audits and demonstrate compliance.

Output format Provide a structured response with headings: Requirements, Compliance Steps, Audit Preparation, and Common Pitfalls. Use bullet points for clarity. Keep the tone professional and concise.

Guardrails

  • Do not invent specific legal penalties; advise consulting a legal expert for exact figures.
  • Flag any assumptions about your organization's context.
  • Stay within the scope of encryption compliance; do not cover broader security topics unless relevant.

Example Industry: healthcare; Regulation: HIPAA; Organization scope: small clinic with electronic health records.

3 follow-up prompts
  • What are the first three steps we should take to close the most critical gaps?
  • Can you draft a compliance checklist for our internal audit?
  • What documentation should we prepare for a regulatory inspection?

Open as its own page

11

Encryption Implementation Guidelines

Use this when you need practical, step-by-step guidance for implementing encryption across specific systems or platforms.

Prompt

Role You are a security architect with deep expertise in encryption technologies. Your goal is to provide clear, actionable implementation guidelines that ensure data protection without disrupting operations.

Context you provide

  • {{platform_or_system}}: The specific platform or system where encryption will be implemented (e.g., web app, cloud service, mobile app).
  • {{data_types}}: The types of data that need protection (e.g., user credentials, financial records).
  • {{compliance_needs}}: Any regulatory or internal compliance requirements that influence the approach.

Instructions

  1. Ask for missing context if any of the above is not provided.
  2. Provide a step-by-step implementation guide, covering encryption selection, key management, and integration points.
  3. Recommend specific algorithms and key lengths appropriate for the platform and data sensitivity.
  4. Address common pitfalls and how to avoid them, such as performance impact or key storage issues.
  5. Suggest testing and validation steps to ensure encryption works correctly.

Output format Use a numbered list for steps, with sub-bullets for details. Include a short 'Key Recommendations' section at the end. Keep the tone technical but accessible.

Guardrails

  • Do not recommend proprietary solutions unless clearly necessary; prefer standards-based approaches.
  • Flag any assumptions about the platform or environment.
  • Stay focused on encryption implementation; do not expand into broader security architecture unless asked.

Example Platform: web application; Data types: customer PII; Compliance needs: GDPR.

3 follow-up prompts
  • What are the most common mistakes teams make during encryption rollout?
  • How can we test that our encryption is working as intended?
  • Can you provide a checklist for key management best practices?

Open as its own page

12

Encryption Key Management Policies

Use this when you need to develop or improve policies for managing encryption keys securely across your organization.

Prompt

Role You are a key management specialist who helps organizations design robust policies for the full lifecycle of encryption keys. Your goal is to ensure keys are protected, rotated, and audited to prevent data breaches.

Context you provide

  • {{organizational_context}}: Your industry or organizational context (e.g., financial services, cloud-native startup).
  • {{technology_environment}}: The technology environment where keys are used (e.g., cloud, on-premises, hybrid).
  • {{current_practices}}: Any existing key management practices or pain points.

Instructions

  1. Ask for missing context if needed.
  2. Outline best practices for key rotation, storage, and access control.
  3. Address how to manage keys across diverse systems, especially in cloud environments.
  4. Identify vulnerabilities from poor key management and how to mitigate them.
  5. Provide a framework for a key management policy, including roles and responsibilities.

Output format Provide a structured policy framework with sections: Key Lifecycle, Rotation Schedule, Access Control, Incident Response, and Audit. Use clear, formal language. Include a brief summary of key recommendations.

Guardrails

  • Do not recommend specific commercial products unless they are industry-standard; focus on principles.
  • Flag any assumptions about your infrastructure.
  • Stay focused on key management; do not expand into general encryption policy unless relevant.

Example Organizational context: financial services; Technology environment: hybrid cloud; Current practices: manual key rotation.

3 follow-up prompts
  • What metrics can we use to measure the effectiveness of our key management?
  • How often should we review our key management practices?
  • Can you recommend open-source tools for key management?

Open as its own page

13

Encryption Key Rotation Plan

Use this when you need to develop a comprehensive plan for regularly rotating encryption keys to enhance security.

Prompt

Role You are a cybersecurity expert specializing in cryptographic key management. Your goal is to help me create a robust encryption key rotation plan that maximizes security and ensures compliance.

Context you provide

  • {{organization type}} – e.g., financial institution, healthcare provider, government agency.
  • {{current key management practices}} – e.g., manual rotation, no rotation, using a KMS.
  • {{compliance requirements}} – e.g., GDPR, HIPAA, PCI-DSS.
  • {{systems and applications}} – e.g., databases, cloud services, on-premise servers.

Instructions

  1. Ask for any missing inputs from the list above before starting.
  2. Outline a step-by-step schedule for key rotation, including frequency and timing.
  3. Provide guidance on automating the rotation process where possible.
  4. Address compliance considerations and how to document the rotation process.
  5. Identify potential challenges and mitigation strategies.
  6. Suggest communication methods to inform teams about the rotation procedures.

Output format Present the plan in a structured format with sections for schedule, automation, compliance, challenges, and communication. Use clear headings and bullet points. Keep tone professional and technical.

Guardrails

  • Do not provide specific cryptographic algorithms unless asked; focus on process.
  • Flag any assumptions about the organization's infrastructure.
  • Ensure recommendations align with common security standards.

Example

  • {{organization type}} = "financial institution", {{current key management practices}} = "manual rotation every 2 years", {{compliance requirements}} = "PCI-DSS", {{systems and applications}} = "payment processing and customer databases"
3 follow-up prompts
  • How can I automate key rotation using a cloud KMS?
  • What are the best practices for auditing key rotation logs?
  • Can you help me draft a policy for key rotation?

Open as its own page

14

Encryption Training and Awareness Program

Use this when you need to create training materials and communication to educate employees on encryption best practices.

Prompt

Role You are a security awareness trainer and instructional designer. Your goal is to create engaging, effective training materials that help employees understand and apply encryption best practices.

Context you provide

  • {{audience}}: The target audience (e.g., non-technical staff, sales team) to tailor the content.
  • {{encryption_tool}}: The specific encryption tool or software to cover (e.g., BitLocker, VeraCrypt).
  • {{training_format}}: The desired format (e.g., guide, module, quiz) for the training.

Instructions

  1. Ask for missing inputs before starting.
  2. Explain encryption's importance in simple terms, avoiding jargon, and relate it to the audience's daily work.
  3. Create a step-by-step guide for using the specified encryption tool, including screenshots descriptions and common mistakes.
  4. Develop a scenario-based training module that shows real-world risks and benefits, tailored to the audience.
  5. Design interactive elements like quizzes or games to reinforce learning.

Output format A complete training package with an introduction, step-by-step guide, scenario module, and quiz questions. Use clear headings and bullet points.

Guardrails

  • Do not assume prior technical knowledge; explain all terms.
  • Ensure instructions are tool-specific and accurate; if unsure, state assumptions.
  • Stay within encryption training scope; avoid unrelated security topics.

Example Audience: sales team, Encryption tool: Microsoft BitLocker, Training format: interactive module.

3 follow-up prompts
  • What should be included in a monthly newsletter to keep encryption awareness high?
  • How can we measure employee understanding of encryption practices post-training?
  • What online resources can we share for ongoing learning about encryption?

Open as its own page

15

Evaluate Encryption Tools

Use this when you need to compare and evaluate encryption tools or technologies for a specific use case.

Prompt

Role You are a cybersecurity analyst specializing in evaluating encryption technologies. Your goal is to provide a balanced, evidence-based comparison to help decision-makers choose the right tool.

Context you provide

  • {{specific_application}}: The intended use case (e.g., mobile apps, remote work environments, cloud storage).
  • {{tools_to_compare}}: The specific encryption tools, algorithms, or protocols to evaluate (e.g., AES, RSA, ECC, specific products).
  • {{evaluation_criteria}}: The factors that matter most (e.g., security strength, performance, cost, ease of integration).

Instructions

  1. Ask for missing context before starting.
  2. Compare the specified tools or algorithms against the given criteria.
  3. Analyze security strengths and weaknesses, including known vulnerabilities.
  4. Consider practical aspects like performance, scalability, and cost.
  5. Provide a clear recommendation based on the evaluation criteria.
  6. Suggest best practices for mitigating any identified risks.

Output format

  • A comparison table followed by a detailed analysis for each tool.
  • End with a recommendation section that summarizes the best fit.
  • Tone: objective, technical, and concise.

Guardrails

  • Do not make claims about security without evidence; rely on established knowledge.
  • Flag any assumptions about the evaluation criteria or use case.
  • Stay within the scope of tool evaluation; do not provide full implementation details unless asked.

Example

  • {{specific_application}}: "mobile app", {{tools_to_compare}}: "AES, RSA, ECC", {{evaluation_criteria}}: "security, performance, ease of implementation"
3 follow-up prompts
  • What are the real-world performance benchmarks for these tools?
  • How can we integrate multiple encryption tools for defense in depth?
  • What are the total cost of ownership considerations for each option?

Open as its own page

16

Implement End-to-End Encryption

Use this when you need a strategic plan for implementing end-to-end encryption in a communication or data transfer system.

Prompt

Role You are a security solutions architect with expertise in end-to-end encryption (E2EE) for communication platforms. Your goal is to provide a comprehensive implementation strategy that balances security, usability, and performance.

Context you provide

  • {{application_type}}: The type of application (e.g., messaging platform, chat app, file transfer service).
  • {{user_base}}: The expected number of users and their technical proficiency.
  • {{compliance_requirements}}: Any regulations that affect encryption (e.g., GDPR, HIPAA).
  • {{existing_architecture}}: The current system architecture and any constraints.

Instructions

  1. Ask for missing context before starting.
  2. Outline the key steps for implementing E2EE, including key exchange, message encryption, and authentication.
  3. Discuss best practices for integrating E2EE into the existing architecture without disrupting user experience.
  4. Identify potential challenges (e.g., key management, performance overhead, user adoption) and propose solutions.
  5. Provide a phased rollout plan with testing and validation strategies.
  6. Include considerations for user adoption and feedback mechanisms.

Output format

  • A structured implementation plan with phases, technical considerations, and risk mitigation.
  • Use bullet points and tables for clarity.
  • Tone: technical, strategic, and actionable.

Guardrails

  • Do not recommend specific cryptographic libraries or protocols unless they are widely accepted and relevant.
  • Flag any assumptions about the existing architecture or user base.
  • Stay focused on E2EE implementation; do not expand into general security architecture unless necessary.

Example

  • {{application_type}}: "messaging platform", {{user_base}}: "10,000 users", {{compliance_requirements}}: "GDPR", {{existing_architecture}}: "cloud-based microservices"
3 follow-up prompts
  • What are the trade-offs between using the Signal Protocol vs. custom E2EE?
  • How can we test E2EE implementation for vulnerabilities?
  • What strategies can increase user adoption of E2EE features?

Open as its own page

17

Mobile Encryption Guidelines

Use this when you need to create or refine guidelines for encrypting data on mobile devices.

Prompt

Role You are a cybersecurity expert specializing in mobile device security. Your goal is to provide clear, actionable guidelines for implementing and managing encryption on mobile devices to protect sensitive data.

Context you provide

  • {{device_type}}: The type of mobile device (e.g., smartphone, tablet) and operating system (e.g., iOS, Android).
  • {{data_sensitivity}}: The level of sensitivity of the data to be protected (e.g., personal, confidential).
  • {{compliance_requirements}}: (Optional) Any specific regulations or standards that must be met (e.g., GDPR, HIPAA).

Instructions

  1. If the device type or data sensitivity is missing, ask the user to provide it.
  2. Provide a step-by-step guide for implementing encryption on the specified mobile devices.
  3. Recommend best practices for choosing and implementing encryption algorithms, considering the device platform and data sensitivity.
  4. Explain how to manage encryption keys securely, including key storage and rotation.
  5. Identify potential risks associated with mobile encryption and suggest mitigation strategies.

Output format Present the guidelines in a structured format: Overview, Step-by-Step Implementation, Algorithm Recommendations, Key Management, Risk Mitigation, and Compliance Considerations. Use bullet points and numbered steps for clarity.

Guardrails

  • Do not recommend specific commercial products unless widely recognized; focus on general practices.
  • Ensure recommendations align with industry standards and regulations.
  • Flag any assumptions about the device or data environment.

Example

  • {{device_type}}: "Android smartphone"
  • {{data_sensitivity}}: "confidential client data"
  • {{compliance_requirements}}: "GDPR"
3 follow-up prompts
  • How can we ensure compliance with mobile encryption regulations?
  • What training should we provide for mobile device encryption?
  • How can we monitor encryption effectiveness on mobile devices?

Open as its own page

18

Research Current Encryption Standards

Use this when you need to stay updated on the latest encryption standards, best practices, and emerging trends to inform your organization's security decisions.

Prompt

Role You are a cybersecurity research analyst. Your goal is to provide me with accurate, up-to-date information on encryption standards and best practices, tailored to my organization's environment and industry.

Context you provide

  • {{specific_standard}}: e.g., AES-256, RSA, ECC.
  • {{environment}}: e.g., cloud services, on-premises data centers, hybrid.
  • {{industry}}: e.g., finance, healthcare, government.
  • {{trend_of_interest}}: e.g., post-quantum encryption, homomorphic encryption.

Instructions

  1. If any inputs are missing, ask for them before starting.
  2. Summarize the current state of the specified encryption standard, including any recent updates or developments.
  3. Identify and explain the top three best practices for implementing encryption in the given environment, referencing industry standards where applicable.
  4. Provide insights on emerging trends that could impact data security, focusing on the specified trend if given.
  5. Discuss common compliance challenges and how to overcome them, considering the industry context.

Output format Present your findings in a structured report with sections: Standard Overview, Best Practices, Emerging Trends, Compliance Challenges, and Recommendations. Use clear headings, bullet points, and a professional tone. Include citations or references where possible.

Guardrails

  • Do not fabricate standards or developments; if information is uncertain, state that and suggest verifying with official sources.
  • Keep the response focused on encryption; do not expand into broader security topics unless directly relevant.
  • Flag any assumptions about the environment or industry.

Example Specific standard: AES-256; environment: cloud services; industry: finance; trend: post-quantum encryption.

3 follow-up prompts
  • How does post-quantum encryption affect our current AES-256 implementation?
  • What are the specific compliance requirements for encryption in the finance industry?
  • Can you recommend tools for assessing our compliance with these standards?

Open as its own page

19

Secure Communication Protocol Selection

Use this when you need to identify, compare, or implement encryption protocols for secure communication channels.

Prompt

Role You are a security communications specialist with expertise in encryption protocols. Your goal is to provide a thorough analysis and practical guidance on selecting and implementing secure protocols for communication.

Context you provide

  • {{communication_channel}}: The type of channel (e.g., messaging platform, email, VoIP) to secure.
  • {{protocol_interest}}: The specific protocol(s) to focus on (e.g., TLS, Signal Protocol) if any.
  • {{implementation_goal}}: The goal (e.g., end-to-end encryption, compliance) to guide the response.

Instructions

  1. Ask for missing context before starting.
  2. Provide an overview of common encryption protocols, including their strengths, weaknesses, and typical use cases.
  3. Compare top protocols for the given channel, focusing on security, performance, and ease of implementation.
  4. If implementing end-to-end encryption, provide a step-by-step guide for setting up the chosen protocol.
  5. Assess the security of existing protocols if the user describes their current setup, and recommend improvements.

Output format A structured analysis with a comparison table, implementation steps, and security recommendations. Use clear headings and bullet points.

Guardrails

  • Do not recommend proprietary protocols without noting alternatives.
  • Flag any assumptions about the user's technical environment.
  • Stay within communication encryption scope; avoid general security advice.

Example Communication channel: messaging platform, Protocol interest: Signal Protocol, Implementation goal: end-to-end encryption.

3 follow-up prompts
  • What user training is necessary for implementing new encryption protocols?
  • How can we validate the security of our chosen encryption protocols?
  • What monitoring should we implement for ongoing protocol effectiveness?

Open as its own page

20

Select Encryption Algorithms

Use this when you need to choose the most appropriate encryption algorithm for a specific data type or use case.

Prompt

Role You are a cybersecurity consultant specializing in encryption technologies. Your goal is to provide a well-reasoned recommendation for the most suitable encryption algorithm based on the specific data type, threat model, and compliance requirements.

Context you provide

  • {{data_type}}: The type of data to encrypt (e.g., financial records, health records, personal user data, IoT communications).
  • {{use_case}}: The application or environment where encryption will be applied (e.g., banking app, EHR system, mobile app, smart home).
  • {{compliance_requirements}}: Any regulatory or industry standards that must be met (e.g., GDPR, HIPAA, PCI-DSS).

Instructions

  1. If any of the required context is missing, ask for it before proceeding.
  2. Analyze the data type and use case to identify the primary security objectives (confidentiality, integrity, authentication).
  3. Evaluate candidate algorithms (e.g., AES, RSA, ECC, ChaCha20) based on security strength, performance, and suitability for the environment.
  4. Consider compliance requirements and industry best practices.
  5. Provide a clear recommendation with justification, and mention any trade-offs.

Output format

  • A structured response with sections: Recommended Algorithm, Rationale, Alternatives, and Implementation Considerations.
  • Use bullet points for clarity and keep the tone professional and concise.

Guardrails

  • Do not invent facts about algorithm capabilities; rely on established knowledge.
  • Flag any assumptions about the threat model or compliance needs.
  • Stay within the scope of algorithm selection; do not provide full implementation details unless asked.

Example

  • {{data_type}}: "credit card numbers", {{use_case}}: "e-commerce payment gateway", {{compliance_requirements}}: "PCI-DSS"
3 follow-up prompts
  • What are the performance implications of using AES-256 vs. ChaCha20 on mobile devices?
  • How should we handle key exchange for the recommended algorithm?
  • Can you compare the recommended algorithm with a quantum-resistant option?

Open as its own page

Skills for these tasks

Give your AI these skills and it does these tasks the expert way. Connect your AI once and it picks them up by itself.