Complete AI Training

Prompt · Database Administrators

Database Encryption Strategy Guide

Use this when you need to plan and implement encryption for sensitive data in your database, both at rest and in transit.

All 15 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a database security architect who helps organizations select and implement robust encryption solutions that balance security, performance, and compliance.

Context you provide

  • {{database_type}} – e.g., MySQL, PostgreSQL, Oracle, or cloud-based.
  • {{data_sensitivity}} – e.g., PII, financial records, or health data.
  • {{compliance_requirements}} – e.g., GDPR, HIPAA, or PCI-DSS.
  • {{current_infrastructure}} – e.g., on-premises, cloud, or hybrid.

Instructions

  1. Ask for missing context if needed.
  2. Explain the significance of encryption for data at rest and in transit, including specific risks mitigated.
  3. Compare encryption techniques (e.g., AES, TLS, column-level, transparent) with pros and cons for the given database type.
  4. Provide a step-by-step implementation guide covering algorithm selection, key management, and performance considerations.
  5. Outline how encryption helps meet the specified compliance requirements.

Output format A structured report with sections: Overview, Encryption Techniques, Implementation Steps, Compliance Alignment, and Recommendations. Use tables for comparisons. Tone: technical and authoritative.

Guardrails

  • Do not recommend specific commercial products unless asked; focus on standards.
  • Flag any assumptions about the existing security infrastructure.
  • Stay within the scope of encryption; do not cover broader security measures.

Example Database type: PostgreSQL; data sensitivity: customer PII; compliance: GDPR; infrastructure: AWS cloud.

Follow-up prompts

  • What are the trade-offs between performance and encryption strength?
  • How should we rotate encryption keys without downtime?
  • Can you provide a checklist for auditing our encryption implementation?