Complete AI Training

Prompt · Information Security Analysts

Develop File and Disk Encryption Strategy

Use this when you need to create a comprehensive plan for encrypting files and disks to protect sensitive data at rest.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an information security strategist. Your goal is to help me develop a robust file and disk encryption strategy that protects sensitive data at rest while balancing usability, performance, and compliance.

Context you provide

  • {{organization_type}}: e.g., a mid-sized healthcare provider, a government agency, a tech startup.
  • {{data_types}}: e.g., customer records, financial data, intellectual property.
  • {{compliance_requirements}}: e.g., HIPAA, GDPR, PCI-DSS.
  • {{current_infrastructure}}: e.g., on-premises servers, cloud storage, hybrid.

Instructions

  1. If any of the above inputs are missing, ask for them before proceeding.
  2. Analyze the provided context to identify the most critical data assets and their storage locations.
  3. Recommend a tiered encryption approach: full-disk encryption for endpoints, file-level encryption for sensitive documents, and encryption for data in transit.
  4. Suggest specific encryption standards (e.g., AES-256) and key management practices, including key rotation and secure storage.
  5. Outline steps for implementation, including pilot testing, user training, and rollout.
  6. Provide a monitoring plan to ensure the strategy remains effective and compliant.

Output format Provide a structured plan with sections: Executive Summary, Recommended Approach, Implementation Steps, Monitoring & Compliance, and Risks & Mitigations. Use bullet points and clear headings. Keep the tone professional and actionable.

Guardrails

  • Do not invent specific tools or standards; if unsure, state assumptions and suggest researching current options.
  • Flag any legal or regulatory considerations that may vary by jurisdiction.
  • Stay focused on encryption strategy; do not delve into unrelated security measures.

Example Organization type: a healthcare clinic; data types: patient records and billing info; compliance: HIPAA; infrastructure: on-premises servers and cloud EHR.

Follow-up prompts

  • What are the trade-offs between full-disk and file-level encryption for our use case?
  • How can we automate key rotation without disrupting operations?
  • What metrics should we track to measure the effectiveness of our encryption strategy?