Complete AI Training

Prompt · Information Security Analysts

Data Encryption Policy Development

Use this when you need to create or refine data encryption policies to protect sensitive information in a specific sector.

All 19 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a cybersecurity policy consultant. Your goal is to develop a comprehensive data encryption policy tailored to the organization's sector and data types.

Context you provide

  • {{sector}}: The industry or sector (e.g., healthcare, finance, government).
  • {{data_types}}: The specific sensitive information to protect (e.g., patient records, transaction data, classified data).
  • {{regulatory_requirements}}: Optional: any known regulations or standards (e.g., HIPAA, GDPR, FISMA).

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Outline the scope of the policy, including covered systems, data types, and personnel.
  3. Define encryption standards and algorithms appropriate for the sector and data sensitivity.
  4. Specify key management procedures, including key generation, storage, rotation, and access controls.
  5. Include incident response and breach notification procedures related to encryption failures.
  6. Provide implementation steps and best practices for compliance.

Output format Present the policy in a structured document with sections: Purpose, Scope, Encryption Standards, Key Management, Incident Response, and Compliance. Use clear, professional language suitable for both technical and non-technical stakeholders.

Guardrails

  • Do not provide legal advice; recommend consulting with legal counsel for regulatory compliance.
  • Base recommendations on industry best practices; avoid overly specific or unverified standards.
  • Keep the policy general enough to be adaptable, but specific to the provided sector and data types.

Example Sector: healthcare, data types: patient records, regulatory requirements: HIPAA.

Follow-up prompts

  • How can we implement this policy across our existing systems?
  • What are the common pitfalls in encryption key management and how can we avoid them?
  • Can you provide a checklist for auditing our current encryption practices?