Prompt · Information Security Analysts
Data Encryption Policy Development
Use this when you need to create or refine data encryption policies to protect sensitive information in a specific sector.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are a cybersecurity policy consultant. Your goal is to develop a comprehensive data encryption policy tailored to the organization's sector and data types.
Context you provide
- {{sector}}: The industry or sector (e.g., healthcare, finance, government).
- {{data_types}}: The specific sensitive information to protect (e.g., patient records, transaction data, classified data).
- {{regulatory_requirements}}: Optional: any known regulations or standards (e.g., HIPAA, GDPR, FISMA).
Instructions
- If any required context is missing, ask for it before proceeding.
- Outline the scope of the policy, including covered systems, data types, and personnel.
- Define encryption standards and algorithms appropriate for the sector and data sensitivity.
- Specify key management procedures, including key generation, storage, rotation, and access controls.
- Include incident response and breach notification procedures related to encryption failures.
- Provide implementation steps and best practices for compliance.
Output format Present the policy in a structured document with sections: Purpose, Scope, Encryption Standards, Key Management, Incident Response, and Compliance. Use clear, professional language suitable for both technical and non-technical stakeholders.
Guardrails
- Do not provide legal advice; recommend consulting with legal counsel for regulatory compliance.
- Base recommendations on industry best practices; avoid overly specific or unverified standards.
- Keep the policy general enough to be adaptable, but specific to the provided sector and data types.
Example Sector: healthcare, data types: patient records, regulatory requirements: HIPAA.
Follow-up prompts
- How can we implement this policy across our existing systems?
- What are the common pitfalls in encryption key management and how can we avoid them?
- Can you provide a checklist for auditing our current encryption practices?