ISMS Copilot Docs

Kryptographie- und Datenschutz-Prompts

Implementieren Sie kryptografische Kontrollen und Datenschutzmechanismen, die ISO 27001 Annex A.10 und A.8.11, GDPR Artikel 32 und 34, SOC 2 CC6.7 und NIST… entsprechen

Was Sie erreichen werden

Implementieren Sie kryptografische Kontrollen und Datenschutzmechanismen, die den Anforderungen von ISO 27001 Annex A.10 und A.8.11, GDPR Artikel 32 und 34, SOC 2 CC6.7 sowie den kryptografischen Standards NIST SP 800-57/800-175 entsprechen. Diese Prompts helfen Ihnen, Verschlüsselungs-, Schlüsselmanagement- und Datenverarbeitungssysteme zu entwerfen.

Kryptografiestrategie und -richtlinie

Kryptografie-Richtlinie und -Standards

Create a cryptography policy for [organization] covering [use cases]. Include:
- Approved encryption algorithms (AES-256, RSA-2048/4096, ECDSA, etc.)
- Deprecated/forbidden algorithms (DES, MD5, SHA-1, RC4)
- Key lengths and rotation requirements by use case
- Encryption use cases (data at rest, data in transit, backups, removable media)
- Key management responsibilities
- Cryptographic library and tool standards
- Random number generation requirements
- Quantum-resistant cryptography roadmap
- Export control and regulatory compliance
- Exception process and risk acceptance
- Compliance mapping (ISO 27001 A.10.1, GDPR Art. 32, SOC 2 CC6.7, NIST SP 800-175)

Output as policy document and approved algorithms matrix.

Auswahl kryptografischer Kontrollen

Design cryptographic control selection framework for [data types/systems]. For each asset category, specify:
- Data classification level
- Encryption-at-rest requirements (algorithm, key type, key management)
- Encryption-in-transit requirements (TLS version, certificate requirements)
- Hashing requirements (for integrity, passwords, digital signatures)
- Key storage mechanism (HSM, KMS, software vault)
- Performance and compatibility considerations
- Regulatory requirements (GDPR, HIPAA, PCI DSS)
- Cost implications
- Implementation priority

Include decision matrix and technical specifications.

Schlüsselmanagement

Architektur des Schlüsselmanagementsystems (KMS)

Design a key management system for [organization] using [AWS KMS/Azure Key Vault/GCP Cloud KMS/HashiCorp Vault/on-premises HSM]. Include:
- Key hierarchy (master key, data encryption keys, key encryption keys)
- Key generation and entropy sources
- Key storage (HSM, software, cloud KMS)
- Access controls and authentication (RBAC, MFA for key operations)
- Key rotation schedule (automated/manual, frequency)
- Key versioning and history
- Key backup and disaster recovery
- Key destruction and sanitization
- Audit logging of all key operations
- Integration with applications and infrastructure
- Compliance requirements (FIPS 140-2/3, PCI DSS, GDPR)

Map to ISO 27001 A.8.24, SOC 2 CC6.7, NIST SP 800-57.

Verfahren zum Schlüssel-Lebenszyklusmanagement

Create key lifecycle procedures covering all phases for [environment]. Address:

Generation:
- Approved key generation methods
- Randomness requirements (CSPRNG)
- Key strength by purpose

Distribution:
- Secure key transport mechanisms
- Initial key loading procedures
- Key wrapping and encryption

Storage:
- HSM vs. software storage criteria
- Access controls and segregation
- Backup and redundancy

Usage:
- Approved cryptographic operations
- Usage monitoring and anomaly detection
- Performance considerations

Rotation:
- Rotation triggers (time, usage, compromise)
- Automated vs. manual rotation
- Zero-downtime rotation procedures

Destruction:
- Secure deletion methods (cryptographic erasure, physical destruction)
- Certificate revocation
- Audit trail retention

Document for ISO 27001 A.8.24, SOC 2 CC6.7.

Zertifikatsmanagement und PKI

Design Public Key Infrastructure (PKI) and certificate management for [organization]. Include:
- Certificate Authority strategy (internal CA, public CA, hybrid)
- Certificate types and use cases (TLS/SSL, code signing, email, client auth)
- Certificate lifecycle (request, issuance, renewal, revocation)
- Automated certificate management (ACME protocol, Let's Encrypt, ACM)
- Certificate inventory and expiration monitoring
- Revocation checking (CRL, OCSP)
- Private key protection and storage
- Wildcard vs. specific certificate policy
- Certificate pinning considerations
- Disaster recovery (CA backup, escrow)
- Compliance requirements (CA/Browser Forum, PCI DSS, ISO 27001 A.10.1)

Include architecture diagram and runbooks.

Implementierung der Datenverschlüsselung

Verschlüsselungsstrategie für Datenbanken

Create database encryption architecture for [database types]. Include:

Transparent Data Encryption (TDE):
- TDE implementation ([SQL Server/Oracle/MySQL/PostgreSQL])
- Key management integration
- Performance impact mitigation

Column-level encryption:
- Sensitive field identification
- Application-layer vs. database-layer encryption
- Key per tenant/customer considerations

Backup encryption:
- Backup encryption methods
- Key management for backup keys
- Restore procedures and key availability

Always Encrypted / Client-side encryption:
- Use cases and limitations
- Key distribution to applications
- Search and query implications

Map to GDPR Art. 32, PCI DSS Req. 3, ISO 27001 A.8.24, SOC 2 CC6.7.

Verschlüsselung von Datei- und Objektspeichern

Design encryption for file and object storage in [cloud/on-premises]. Include:

Cloud object storage (S3/Blob/GCS):
- Server-side encryption (SSE-S3, SSE-KMS, SSE-C for AWS)
- Client-side encryption before upload
- Bucket policies to enforce encryption
- Key management (customer-managed vs. provider-managed)
- Access controls and least privilege

File servers:
- Full disk encryption (BitLocker, LUKS, FileVault)
- File-level encryption for sensitive data
- Network share encryption (SMB 3.0 encryption)
- Encrypted backup integration

Removable media:
- USB encryption requirements
- Authorized device management
- Data loss prevention integration

Align with ISO 27001 A.8.24, GDPR Art. 32, SOC 2 CC6.7.

Verschlüsselung auf Anwendungsebene

Implement application-layer encryption for [application type]. Include:
- Field-level encryption for PII/PCI data
- Encryption library selection ([language]-specific, vetted libraries)
- Secure key injection (environment variables, secrets manager)
- Envelope encryption pattern (data key + key encryption key)
- Initialization vector (IV) generation and handling
- Authenticated encryption (AES-GCM, ChaCha20-Poly1305)
- Key rotation without data re-encryption (versioned DEKs)
- Search on encrypted data (deterministic encryption, tokenization, format-preserving encryption)
- Performance optimization (caching, async encryption)
- Error handling (key unavailable, decryption failure)

Map to ISO 27001 A.14.1.2, SOC 2 CC6.7, OWASP cryptographic guidance.

Datenklassifizierung und -handhabung

Datenklassifizierungsschema

Create a data classification framework for [organization]. Define:

Classification levels (e.g., Public, Internal, Confidential, Restricted):
- Definition und Beispiele für jede Stufe
- Regulatorische Zuordnung (GDPR-Sonderkategorien, HIPAA PHI, PCI DSS-Kartendaten)
- Handhabungsanforderungen (Verschlüsselung, Zugriffskontrollen, Aufbewahrung, Entsorgung)
- Kennzeichnungs- und Markierungsanforderungen
- Übertragungsbeschränkungen (verschlüsselte Kanäle, zugelassene Methoden)
- Speicheranforderungen (zugelassene Standorte, Verschlüsselung)

Implementation:
- Data discovery and classification tools ([Microsoft Purview/Varonis/BigID])
- User training and responsibilities
- Automated tagging and DLP integration
- Declassification and downgrade procedures
- Audit and compliance validation

Map to ISO 27001 A.8.2, GDPR Art. 5, SOC 2 CC6.7.

Datenminimierung und -aufbewahrung

Design data minimization and retention program for [organization]. Include:
- Dateninventar und -zuordnung (welche Daten, warum erhoben, wo gespeichert)
- Rechtliche Grundlage und Zweckbindung (GDPR Art. 5, 6)
- Reduzierung der Erhebung (nur notwendige Daten)
- Aufbewahrungsfristen nach Datentyp (rechtlich, regulatorisch, geschäftliche Notwendigkeit)
- Automatisierte Lösch-/Anonymisierungsworkflows
- Verfahren für rechtliche Aufbewahrungspflichten
- Abstimmung der Backup-Aufbewahrung
- Umsetzung der Betroffenenrechte (Löschung, Datenübertragbarkeit)
- Dokumentation für die Compliance (Datenschutz-Folgenabschätzungen)
- Regelmäßiger Überprüfungs- und Aktualisierungsprozess

Align with GDPR Art. 5, 17, 25, ISO 27001 A.8.10, SOC 2 CC6.5.

Datenmaskierung und -anonymisierung

Create data masking and anonymization strategy for [use cases]. Include:

Static data masking:
- Irreversible Maskierung für Nicht-Produktionsumgebungen
- Wahrung der referenziellen Integrität
- Techniken (Substitution, Shuffling, Zahlenvarianz)
- Testen und Validierung

Dynamic data masking:
- Echtzeit-Maskierung basierend auf Benutzerrolle
- Anwendungsintegration
- Leistungsüberlegungen

Tokenization:
- Token-Vault-Architektur
- Formatbewahrende Tokenisierung
- Detokenisierungs-Kontrollen

Pseudonymization:
- GDPR Art. 4(5)-Compliance
- Schlüsselmanagement für Pseudonyme
- Verhinderung der Re-Identifizierung

Synthetic data generation:
- Beibehaltung statistischer Eigenschaften
- Anwendungsfälle (ML-Training, Testen)

Map to GDPR Art. 25, 32, ISO 27001 A.8.11, SOC 2 CC6.7.

Sichere Datenvernichtung

Datenbereinigung und -entsorgung

Create data sanitization procedures for [asset types]. Address:

Electronic media:
- Hard drives: Überschreiben (DoD 5220.22-M, NIST SP 800-88), Entmagnetisieren, physische Zerstörung
- SSDs und Flash: kryptografische Löschung, physische Zerstörung (Überschreiben unzuverlässig)
- Cloud storage: kryptografische Löschung durch Schlüsselentfernung, Verifizierung der Anbieterlöschung
- Backup tapes: Entmagnetisieren oder physische Zerstörung
- Mobile devices: Werkseinstellungen + Löschung des Verschlüsselungsschlüssels

Paper documents:
- Schredderanforderungen (Kreuzschnitt, Partikelgröße)
- Zertifizierte Entsorgungsdienstleister

Disposal verification:
- Vernichtungszertifikat
- Prüfpfad und Compliance-Dokumentation
- Integration der Asset-Nachverfolgung

Decommissioning workflow:
- Datensicherung falls erforderlich (rechtliche Aufbewahrungspflicht)
- Auswahl der Bereinigungsmethode
- Durchführung und Verifizierung
- Entsorgung oder Wiederverwendung des Assets

Map to ISO 27001 A.8.10, GDPR Art. 17, NIST SP 800-88, SOC 2 CC6.5.

Umsetzung des Löschrechts (GDPR)

Design technical implementation for GDPR right to erasure (Art. 17). Include:
- Entgegennahme und Verifizierung von Anträgen betroffener Personen
- Datenstandort-Mapping (alle Systeme, Backups, Protokolle, Dritte)
- Automatisierte Löschworkflows
- Umgang mit Backups (Löschung aus Live-Systemen, Dokumentation von Ausnahmen für Backups mit kurzer Aufbewahrungsfrist)
- Benachrichtigung und Koordination der Löschung mit Dritten
- Ausnahmen (rechtliche Verpflichtungen, öffentliches Interesse, lebenswichtige Interessen)
- Verifizierungs- und Bestätigungsprozess
- Einhaltung der Frist (Antwort innerhalb eines Monats)
- Dokumentation für die Aufsichtsbehörde
- Technische Herausforderungen und Lösungen (verteilte Systeme, Blockchain, Archive)

Include request form, workflow diagram, and response templates.

Netzwerk- und Kommunikationsverschlüsselung

TLS/SSL-Konfiguration und -Management

Create TLS/SSL configuration standards for [web servers/load balancers/APIs]. Include:
- Mindest-TLS-Version (TLS 1.2, bevorzugt TLS 1.3)
- Zugelassene Cipher Suites (Forward Secrecy, AEAD-Ciphers)
- Deaktivierte Protokolle (SSLv2, SSLv3, TLS 1.0, TLS 1.1)
- Zertifikatsanforderungen (Schlüssellänge, Signaturalgorithmus, CA)
- HSTS (HTTP Strict Transport Security)-Konfiguration
- OCSP-Stapling für bessere Performance
- Überlegungen zum Certificate Pinning
- Konfigurationstests und -validierung (SSL Labs, testssl.sh)
- Überwachung auf schwache Konfigurationen
- Dokumentation für Audits (ISO 27001 A.13.2.3, A.10.1, SOC 2 CC6.7)

Include configuration examples for [nginx/Apache/IIS/ALB/HAProxy].

E-Mail-Verschlüsselung und -Signatur

Design email security using encryption and signing for [organization]. Include:

Transport encryption:
- TLS-Erzwingung für eingehende/ausgehende E-Mails (SMTP STARTTLS)
- MTA-STS (Mail Transfer Agent Strict Transport Security)
- DANE (DNS-based Authentication of Named Entities)

End-to-end encryption:
- S/MIME-Zertifikatsverteilung und -management
- PGP/GPG-Schlüsselmanagement
- Automatische Verschlüsselung für sensible Datenmuster
- Key-Escrow-Überlegungen (Compliance vs. Datenschutz)

Email signing:
- DKIM (DomainKeys Identified Mail)-Konfiguration
- SPF (Sender Policy Framework)-Einträge
- DMARC (Domain-based Message Authentication)-Richtlinie

User experience:
- Transparente Verschlüsselung wo möglich
- Umgang mit externen Empfängern (sicherer Portalzugang, einmalige Verschlüsselung)
- Schulung und Support

Map to ISO 27001 A.13.2.3, GDPR Art. 32, SOC 2 CC6.7.

VPN- und Remote-Zugriffsverschlüsselung

Create secure remote access architecture using [VPN type/Zero Trust]. Include:
- VPN-Protokollauswahl (IPsec, OpenVPN, WireGuard)
- Authentifizierungsanforderungen (zertifikatsbasiert, MFA)
- Verschlüsselungsstandards (AES-256, starker Schlüsselaustausch)
- Entscheidung zwischen Split-Tunneling und Full-Tunneling
- Zugriffskontrollen und Netzwerksegmentierung
- Protokollierung und Überwachung
- Performance und Skalierbarkeit
- Anforderungen an Client-Geräte und Sicherheitsüberprüfung
- Zero-Trust-Alternative (Identity-Aware Proxy, Zugriff pro Anwendung)
- Migrationsplan von Legacy-VPN

Align with ISO 27001 A.13.2.3, A.9.1.2, SOC 2 CC6.6.

Compliance und Testen

Testen kryptografischer Implementierungen

Design cryptographic validation and testing program for [organization]. Include:
- Automatisiertes Scannen der Konfiguration (SSL/TLS, SSH, Datenbankverschlüsselung)
- Penetrationstests kryptografischer Kontrollen
- Code-Review für Krypto-Implementierungen (häufige Fehler, Bibliotheksmissbrauch)
- Entropie- und Zufälligkeitstests
- Widerstandsfähigkeit gegen Seitenkanalangriffe (Timing, Stromanalyse)
- FIPS 140-2/3-Validierungsanforderungen
- Regelmäßiger Krypto-Audit-Plan (jährlich)
- Schwachstellenbewertung für kryptografische Schwächen
- Integration in CI/CD (Builds bei schwacher Krypto fehlschlagen lassen)
- Dokumentation der Testergebnisse für die Compliance

Map to ISO 27001 A.14.2.8, SOC 2 CC7.1.

Dokumentation der Verschlüsselungs-Compliance

Create encryption compliance evidence package for [ISO 27001/SOC 2/GDPR/HIPAA] audit. Include:
- Kryptografie-Richtlinie und -Standards
- Schlüsselmanagement-Verfahren und -Protokolle
- Inventar der Verschlüsselungsimplementierungen (alle Systeme)
- Konfigurationsexporte und Validierungsberichte
- Protokolle und Pläne zur Schlüsselrotation
- Zugriffskontrollen für Schlüssel und verschlüsselte Daten
- Testergebnisse und Validierungen
- Schulungsunterlagen für Mitarbeiter, die mit Schlüsseln arbeiten
- Vorfallberichte im Zusammenhang mit kryptografischen Kontrollen
- Drittanbieter-Bescheinigungen (FIPS, Common Criteria)
- Risikobewertung für kryptografische Kontrollen

Create evidence collection checklist mapped to control requirements.

Niemals eigene Kryptografie implementieren. Verwenden Sie stets geprüfte, etablierte Bibliotheken und Algorithmen. Kryptografische Fehler können katastrophale Folgen haben und sind schwer zu erkennen.

Laden Sie Ihre aktuelle Verschlüsselungsarchitektur oder Konfigurationsdateien hoch, um eine Gap-Analyse gegenüber aktuellen kryptografischen Standards und Compliance-Anforderungen zu erhalten.

Neue Kryptografie-Entwicklungen

Post-Quantum-Kryptografie-Bereitschaft

Create post-quantum cryptography (PQC) transition plan for [organization]. Include:
- Kryptografie-Inventar (alle Systeme, die Public-Key-Krypto verwenden)
- Zeitplan und Risikobewertung der Quantenbedrohung
- Bewertung der NIST-PQC-Algorithmen (finalisierte Standards)
- Hybridansatz (klassisch + PQC während der Übergangsphase)
- Migrationsplan für die Zertifikatsinfrastruktur
- Anwendungs- und Protokoll-Updates (TLS 1.3 mit PQC)
- Zeitplan und Meilensteine (Krypto-Agilität jetzt, PQC-Migration bis [Datum])
- Kosten- und Aufwandsschätzung
- Testen und Validierung
- Koordination mit Anbietern und Partnern

Reference NIST SP 800-208, CNSA 2.0 timeline.

Verwandte Prompts

  • Siehe Infrastructure and cloud security prompts für Cloud-Verschlüsselungsimplementierungen
  • Siehe Secure development lifecycle prompts für kryptografische Codierungsstandards
  • Siehe Access control and identity management prompts für Authentifizierungsverschlüsselung

On this page