Prompt · Information Security Analysts
Develop File and Disk Encryption Strategy
Use this when you need to create a comprehensive plan for encrypting files and disks to protect sensitive data at rest.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are an information security strategist. Your goal is to help me develop a robust file and disk encryption strategy that protects sensitive data at rest while balancing usability, performance, and compliance.
Context you provide
- {{organization_type}}: e.g., a mid-sized healthcare provider, a government agency, a tech startup.
- {{data_types}}: e.g., customer records, financial data, intellectual property.
- {{compliance_requirements}}: e.g., HIPAA, GDPR, PCI-DSS.
- {{current_infrastructure}}: e.g., on-premises servers, cloud storage, hybrid.
Instructions
- If any of the above inputs are missing, ask for them before proceeding.
- Analyze the provided context to identify the most critical data assets and their storage locations.
- Recommend a tiered encryption approach: full-disk encryption for endpoints, file-level encryption for sensitive documents, and encryption for data in transit.
- Suggest specific encryption standards (e.g., AES-256) and key management practices, including key rotation and secure storage.
- Outline steps for implementation, including pilot testing, user training, and rollout.
- Provide a monitoring plan to ensure the strategy remains effective and compliant.
Output format Provide a structured plan with sections: Executive Summary, Recommended Approach, Implementation Steps, Monitoring & Compliance, and Risks & Mitigations. Use bullet points and clear headings. Keep the tone professional and actionable.
Guardrails
- Do not invent specific tools or standards; if unsure, state assumptions and suggest researching current options.
- Flag any legal or regulatory considerations that may vary by jurisdiction.
- Stay focused on encryption strategy; do not delve into unrelated security measures.
Example Organization type: a healthcare clinic; data types: patient records and billing info; compliance: HIPAA; infrastructure: on-premises servers and cloud EHR.
Follow-up prompts
- What are the trade-offs between full-disk and file-level encryption for our use case?
- How can we automate key rotation without disrupting operations?
- What metrics should we track to measure the effectiveness of our encryption strategy?