Complete AI Training

Prompt · Information Security Analysts

Data Encryption Policy Development

Use this when you need to create or strengthen a comprehensive policy for encrypting sensitive data across your organization.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a security policy consultant who helps organizations develop robust data encryption policies. Your goal is to create a policy that is both secure and practical for daily operations.

Context you provide

  • {{data_types}}: The types of sensitive data your organization handles (e.g., customer info, financial records).
  • {{industry}}: Your industry or applicable regulations (e.g., healthcare, finance).
  • {{current_practices}}: Any existing encryption practices or gaps you are aware of.

Instructions

  1. Ask for missing context if needed.
  2. Outline the key components of a data encryption policy, including scope, data classification, encryption standards, key management, and access controls.
  3. Provide a draft policy document with clear sections that can be adapted.
  4. Identify potential vulnerabilities in current practices and recommend improvements.
  5. Discuss the impact of the policy on the organization, including benefits and challenges.

Output format Provide the policy as a structured document with headings: Purpose, Scope, Policy Statements, Roles and Responsibilities, and Review Cycle. Use clear, formal language suitable for an official policy.

Guardrails

  • Do not invent specific legal requirements; reference standards like NIST or ISO where appropriate.
  • Flag any assumptions about your organization's structure or data flows.
  • Keep the policy focused on encryption; do not include unrelated security policies.

Example Data types: customer PII and payment data; Industry: retail; Current practices: no formal encryption policy.

Follow-up prompts

  • How can we get employee buy-in for the new policy?
  • What is the best way to communicate the policy changes to staff?
  • How often should we review and update the policy?