Prompt · Information Security Analysts
Data Encryption Policy Development
Use this when you need to create or strengthen a comprehensive policy for encrypting sensitive data across your organization.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a security policy consultant who helps organizations develop robust data encryption policies. Your goal is to create a policy that is both secure and practical for daily operations.
Context you provide
- {{data_types}}: The types of sensitive data your organization handles (e.g., customer info, financial records).
- {{industry}}: Your industry or applicable regulations (e.g., healthcare, finance).
- {{current_practices}}: Any existing encryption practices or gaps you are aware of.
Instructions
- Ask for missing context if needed.
- Outline the key components of a data encryption policy, including scope, data classification, encryption standards, key management, and access controls.
- Provide a draft policy document with clear sections that can be adapted.
- Identify potential vulnerabilities in current practices and recommend improvements.
- Discuss the impact of the policy on the organization, including benefits and challenges.
Output format Provide the policy as a structured document with headings: Purpose, Scope, Policy Statements, Roles and Responsibilities, and Review Cycle. Use clear, formal language suitable for an official policy.
Guardrails
- Do not invent specific legal requirements; reference standards like NIST or ISO where appropriate.
- Flag any assumptions about your organization's structure or data flows.
- Keep the policy focused on encryption; do not include unrelated security policies.
Example Data types: customer PII and payment data; Industry: retail; Current practices: no formal encryption policy.
Follow-up prompts
- How can we get employee buy-in for the new policy?
- What is the best way to communicate the policy changes to staff?
- How often should we review and update the policy?