Kryptographie- und Datenschutz-Prompts
Implementieren Sie kryptografische Kontrollen und Datenschutzmechanismen, die ISO 27001 Annex A.10 und A.8.11, GDPR Artikel 32 und 34, SOC 2 CC6.7 und NIST… entsprechen
Was Sie erreichen werden
Implementieren Sie kryptografische Kontrollen und Datenschutzmechanismen, die den Anforderungen von ISO 27001 Annex A.10 und A.8.11, GDPR Artikel 32 und 34, SOC 2 CC6.7 sowie den kryptografischen Standards NIST SP 800-57/800-175 entsprechen. Diese Prompts helfen Ihnen, Verschlüsselungs-, Schlüsselmanagement- und Datenverarbeitungssysteme zu entwerfen.
Kryptografiestrategie und -richtlinie
Kryptografie-Richtlinie und -Standards
Create a cryptography policy for [organization] covering [use cases]. Include:
- Approved encryption algorithms (AES-256, RSA-2048/4096, ECDSA, etc.)
- Deprecated/forbidden algorithms (DES, MD5, SHA-1, RC4)
- Key lengths and rotation requirements by use case
- Encryption use cases (data at rest, data in transit, backups, removable media)
- Key management responsibilities
- Cryptographic library and tool standards
- Random number generation requirements
- Quantum-resistant cryptography roadmap
- Export control and regulatory compliance
- Exception process and risk acceptance
- Compliance mapping (ISO 27001 A.10.1, GDPR Art. 32, SOC 2 CC6.7, NIST SP 800-175)
Output as policy document and approved algorithms matrix.Auswahl kryptografischer Kontrollen
Design cryptographic control selection framework for [data types/systems]. For each asset category, specify:
- Data classification level
- Encryption-at-rest requirements (algorithm, key type, key management)
- Encryption-in-transit requirements (TLS version, certificate requirements)
- Hashing requirements (for integrity, passwords, digital signatures)
- Key storage mechanism (HSM, KMS, software vault)
- Performance and compatibility considerations
- Regulatory requirements (GDPR, HIPAA, PCI DSS)
- Cost implications
- Implementation priority
Include decision matrix and technical specifications.Schlüsselmanagement
Architektur des Schlüsselmanagementsystems (KMS)
Design a key management system for [organization] using [AWS KMS/Azure Key Vault/GCP Cloud KMS/HashiCorp Vault/on-premises HSM]. Include:
- Key hierarchy (master key, data encryption keys, key encryption keys)
- Key generation and entropy sources
- Key storage (HSM, software, cloud KMS)
- Access controls and authentication (RBAC, MFA for key operations)
- Key rotation schedule (automated/manual, frequency)
- Key versioning and history
- Key backup and disaster recovery
- Key destruction and sanitization
- Audit logging of all key operations
- Integration with applications and infrastructure
- Compliance requirements (FIPS 140-2/3, PCI DSS, GDPR)
Map to ISO 27001 A.8.24, SOC 2 CC6.7, NIST SP 800-57.Verfahren zum Schlüssel-Lebenszyklusmanagement
Create key lifecycle procedures covering all phases for [environment]. Address:
Generation:
- Approved key generation methods
- Randomness requirements (CSPRNG)
- Key strength by purpose
Distribution:
- Secure key transport mechanisms
- Initial key loading procedures
- Key wrapping and encryption
Storage:
- HSM vs. software storage criteria
- Access controls and segregation
- Backup and redundancy
Usage:
- Approved cryptographic operations
- Usage monitoring and anomaly detection
- Performance considerations
Rotation:
- Rotation triggers (time, usage, compromise)
- Automated vs. manual rotation
- Zero-downtime rotation procedures
Destruction:
- Secure deletion methods (cryptographic erasure, physical destruction)
- Certificate revocation
- Audit trail retention
Document for ISO 27001 A.8.24, SOC 2 CC6.7.Zertifikatsmanagement und PKI
Design Public Key Infrastructure (PKI) and certificate management for [organization]. Include:
- Certificate Authority strategy (internal CA, public CA, hybrid)
- Certificate types and use cases (TLS/SSL, code signing, email, client auth)
- Certificate lifecycle (request, issuance, renewal, revocation)
- Automated certificate management (ACME protocol, Let's Encrypt, ACM)
- Certificate inventory and expiration monitoring
- Revocation checking (CRL, OCSP)
- Private key protection and storage
- Wildcard vs. specific certificate policy
- Certificate pinning considerations
- Disaster recovery (CA backup, escrow)
- Compliance requirements (CA/Browser Forum, PCI DSS, ISO 27001 A.10.1)
Include architecture diagram and runbooks.Implementierung der Datenverschlüsselung
Verschlüsselungsstrategie für Datenbanken
Create database encryption architecture for [database types]. Include:
Transparent Data Encryption (TDE):
- TDE implementation ([SQL Server/Oracle/MySQL/PostgreSQL])
- Key management integration
- Performance impact mitigation
Column-level encryption:
- Sensitive field identification
- Application-layer vs. database-layer encryption
- Key per tenant/customer considerations
Backup encryption:
- Backup encryption methods
- Key management for backup keys
- Restore procedures and key availability
Always Encrypted / Client-side encryption:
- Use cases and limitations
- Key distribution to applications
- Search and query implications
Map to GDPR Art. 32, PCI DSS Req. 3, ISO 27001 A.8.24, SOC 2 CC6.7.Verschlüsselung von Datei- und Objektspeichern
Design encryption for file and object storage in [cloud/on-premises]. Include:
Cloud object storage (S3/Blob/GCS):
- Server-side encryption (SSE-S3, SSE-KMS, SSE-C for AWS)
- Client-side encryption before upload
- Bucket policies to enforce encryption
- Key management (customer-managed vs. provider-managed)
- Access controls and least privilege
File servers:
- Full disk encryption (BitLocker, LUKS, FileVault)
- File-level encryption for sensitive data
- Network share encryption (SMB 3.0 encryption)
- Encrypted backup integration
Removable media:
- USB encryption requirements
- Authorized device management
- Data loss prevention integration
Align with ISO 27001 A.8.24, GDPR Art. 32, SOC 2 CC6.7.Verschlüsselung auf Anwendungsebene
Implement application-layer encryption for [application type]. Include:
- Field-level encryption for PII/PCI data
- Encryption library selection ([language]-specific, vetted libraries)
- Secure key injection (environment variables, secrets manager)
- Envelope encryption pattern (data key + key encryption key)
- Initialization vector (IV) generation and handling
- Authenticated encryption (AES-GCM, ChaCha20-Poly1305)
- Key rotation without data re-encryption (versioned DEKs)
- Search on encrypted data (deterministic encryption, tokenization, format-preserving encryption)
- Performance optimization (caching, async encryption)
- Error handling (key unavailable, decryption failure)
Map to ISO 27001 A.14.1.2, SOC 2 CC6.7, OWASP cryptographic guidance.Datenklassifizierung und -handhabung
Datenklassifizierungsschema
Create a data classification framework for [organization]. Define:
Classification levels (e.g., Public, Internal, Confidential, Restricted):
- Definition und Beispiele für jede Stufe
- Regulatorische Zuordnung (GDPR-Sonderkategorien, HIPAA PHI, PCI DSS-Kartendaten)
- Handhabungsanforderungen (Verschlüsselung, Zugriffskontrollen, Aufbewahrung, Entsorgung)
- Kennzeichnungs- und Markierungsanforderungen
- Übertragungsbeschränkungen (verschlüsselte Kanäle, zugelassene Methoden)
- Speicheranforderungen (zugelassene Standorte, Verschlüsselung)
Implementation:
- Data discovery and classification tools ([Microsoft Purview/Varonis/BigID])
- User training and responsibilities
- Automated tagging and DLP integration
- Declassification and downgrade procedures
- Audit and compliance validation
Map to ISO 27001 A.8.2, GDPR Art. 5, SOC 2 CC6.7.Datenminimierung und -aufbewahrung
Design data minimization and retention program for [organization]. Include:
- Dateninventar und -zuordnung (welche Daten, warum erhoben, wo gespeichert)
- Rechtliche Grundlage und Zweckbindung (GDPR Art. 5, 6)
- Reduzierung der Erhebung (nur notwendige Daten)
- Aufbewahrungsfristen nach Datentyp (rechtlich, regulatorisch, geschäftliche Notwendigkeit)
- Automatisierte Lösch-/Anonymisierungsworkflows
- Verfahren für rechtliche Aufbewahrungspflichten
- Abstimmung der Backup-Aufbewahrung
- Umsetzung der Betroffenenrechte (Löschung, Datenübertragbarkeit)
- Dokumentation für die Compliance (Datenschutz-Folgenabschätzungen)
- Regelmäßiger Überprüfungs- und Aktualisierungsprozess
Align with GDPR Art. 5, 17, 25, ISO 27001 A.8.10, SOC 2 CC6.5.Datenmaskierung und -anonymisierung
Create data masking and anonymization strategy for [use cases]. Include:
Static data masking:
- Irreversible Maskierung für Nicht-Produktionsumgebungen
- Wahrung der referenziellen Integrität
- Techniken (Substitution, Shuffling, Zahlenvarianz)
- Testen und Validierung
Dynamic data masking:
- Echtzeit-Maskierung basierend auf Benutzerrolle
- Anwendungsintegration
- Leistungsüberlegungen
Tokenization:
- Token-Vault-Architektur
- Formatbewahrende Tokenisierung
- Detokenisierungs-Kontrollen
Pseudonymization:
- GDPR Art. 4(5)-Compliance
- Schlüsselmanagement für Pseudonyme
- Verhinderung der Re-Identifizierung
Synthetic data generation:
- Beibehaltung statistischer Eigenschaften
- Anwendungsfälle (ML-Training, Testen)
Map to GDPR Art. 25, 32, ISO 27001 A.8.11, SOC 2 CC6.7.Sichere Datenvernichtung
Datenbereinigung und -entsorgung
Create data sanitization procedures for [asset types]. Address:
Electronic media:
- Hard drives: Überschreiben (DoD 5220.22-M, NIST SP 800-88), Entmagnetisieren, physische Zerstörung
- SSDs und Flash: kryptografische Löschung, physische Zerstörung (Überschreiben unzuverlässig)
- Cloud storage: kryptografische Löschung durch Schlüsselentfernung, Verifizierung der Anbieterlöschung
- Backup tapes: Entmagnetisieren oder physische Zerstörung
- Mobile devices: Werkseinstellungen + Löschung des Verschlüsselungsschlüssels
Paper documents:
- Schredderanforderungen (Kreuzschnitt, Partikelgröße)
- Zertifizierte Entsorgungsdienstleister
Disposal verification:
- Vernichtungszertifikat
- Prüfpfad und Compliance-Dokumentation
- Integration der Asset-Nachverfolgung
Decommissioning workflow:
- Datensicherung falls erforderlich (rechtliche Aufbewahrungspflicht)
- Auswahl der Bereinigungsmethode
- Durchführung und Verifizierung
- Entsorgung oder Wiederverwendung des Assets
Map to ISO 27001 A.8.10, GDPR Art. 17, NIST SP 800-88, SOC 2 CC6.5.Umsetzung des Löschrechts (GDPR)
Design technical implementation for GDPR right to erasure (Art. 17). Include:
- Entgegennahme und Verifizierung von Anträgen betroffener Personen
- Datenstandort-Mapping (alle Systeme, Backups, Protokolle, Dritte)
- Automatisierte Löschworkflows
- Umgang mit Backups (Löschung aus Live-Systemen, Dokumentation von Ausnahmen für Backups mit kurzer Aufbewahrungsfrist)
- Benachrichtigung und Koordination der Löschung mit Dritten
- Ausnahmen (rechtliche Verpflichtungen, öffentliches Interesse, lebenswichtige Interessen)
- Verifizierungs- und Bestätigungsprozess
- Einhaltung der Frist (Antwort innerhalb eines Monats)
- Dokumentation für die Aufsichtsbehörde
- Technische Herausforderungen und Lösungen (verteilte Systeme, Blockchain, Archive)
Include request form, workflow diagram, and response templates.Netzwerk- und Kommunikationsverschlüsselung
TLS/SSL-Konfiguration und -Management
Create TLS/SSL configuration standards for [web servers/load balancers/APIs]. Include:
- Mindest-TLS-Version (TLS 1.2, bevorzugt TLS 1.3)
- Zugelassene Cipher Suites (Forward Secrecy, AEAD-Ciphers)
- Deaktivierte Protokolle (SSLv2, SSLv3, TLS 1.0, TLS 1.1)
- Zertifikatsanforderungen (Schlüssellänge, Signaturalgorithmus, CA)
- HSTS (HTTP Strict Transport Security)-Konfiguration
- OCSP-Stapling für bessere Performance
- Überlegungen zum Certificate Pinning
- Konfigurationstests und -validierung (SSL Labs, testssl.sh)
- Überwachung auf schwache Konfigurationen
- Dokumentation für Audits (ISO 27001 A.13.2.3, A.10.1, SOC 2 CC6.7)
Include configuration examples for [nginx/Apache/IIS/ALB/HAProxy].E-Mail-Verschlüsselung und -Signatur
Design email security using encryption and signing for [organization]. Include:
Transport encryption:
- TLS-Erzwingung für eingehende/ausgehende E-Mails (SMTP STARTTLS)
- MTA-STS (Mail Transfer Agent Strict Transport Security)
- DANE (DNS-based Authentication of Named Entities)
End-to-end encryption:
- S/MIME-Zertifikatsverteilung und -management
- PGP/GPG-Schlüsselmanagement
- Automatische Verschlüsselung für sensible Datenmuster
- Key-Escrow-Überlegungen (Compliance vs. Datenschutz)
Email signing:
- DKIM (DomainKeys Identified Mail)-Konfiguration
- SPF (Sender Policy Framework)-Einträge
- DMARC (Domain-based Message Authentication)-Richtlinie
User experience:
- Transparente Verschlüsselung wo möglich
- Umgang mit externen Empfängern (sicherer Portalzugang, einmalige Verschlüsselung)
- Schulung und Support
Map to ISO 27001 A.13.2.3, GDPR Art. 32, SOC 2 CC6.7.VPN- und Remote-Zugriffsverschlüsselung
Create secure remote access architecture using [VPN type/Zero Trust]. Include:
- VPN-Protokollauswahl (IPsec, OpenVPN, WireGuard)
- Authentifizierungsanforderungen (zertifikatsbasiert, MFA)
- Verschlüsselungsstandards (AES-256, starker Schlüsselaustausch)
- Entscheidung zwischen Split-Tunneling und Full-Tunneling
- Zugriffskontrollen und Netzwerksegmentierung
- Protokollierung und Überwachung
- Performance und Skalierbarkeit
- Anforderungen an Client-Geräte und Sicherheitsüberprüfung
- Zero-Trust-Alternative (Identity-Aware Proxy, Zugriff pro Anwendung)
- Migrationsplan von Legacy-VPN
Align with ISO 27001 A.13.2.3, A.9.1.2, SOC 2 CC6.6.Compliance und Testen
Testen kryptografischer Implementierungen
Design cryptographic validation and testing program for [organization]. Include:
- Automatisiertes Scannen der Konfiguration (SSL/TLS, SSH, Datenbankverschlüsselung)
- Penetrationstests kryptografischer Kontrollen
- Code-Review für Krypto-Implementierungen (häufige Fehler, Bibliotheksmissbrauch)
- Entropie- und Zufälligkeitstests
- Widerstandsfähigkeit gegen Seitenkanalangriffe (Timing, Stromanalyse)
- FIPS 140-2/3-Validierungsanforderungen
- Regelmäßiger Krypto-Audit-Plan (jährlich)
- Schwachstellenbewertung für kryptografische Schwächen
- Integration in CI/CD (Builds bei schwacher Krypto fehlschlagen lassen)
- Dokumentation der Testergebnisse für die Compliance
Map to ISO 27001 A.14.2.8, SOC 2 CC7.1.Dokumentation der Verschlüsselungs-Compliance
Create encryption compliance evidence package for [ISO 27001/SOC 2/GDPR/HIPAA] audit. Include:
- Kryptografie-Richtlinie und -Standards
- Schlüsselmanagement-Verfahren und -Protokolle
- Inventar der Verschlüsselungsimplementierungen (alle Systeme)
- Konfigurationsexporte und Validierungsberichte
- Protokolle und Pläne zur Schlüsselrotation
- Zugriffskontrollen für Schlüssel und verschlüsselte Daten
- Testergebnisse und Validierungen
- Schulungsunterlagen für Mitarbeiter, die mit Schlüsseln arbeiten
- Vorfallberichte im Zusammenhang mit kryptografischen Kontrollen
- Drittanbieter-Bescheinigungen (FIPS, Common Criteria)
- Risikobewertung für kryptografische Kontrollen
Create evidence collection checklist mapped to control requirements.Niemals eigene Kryptografie implementieren. Verwenden Sie stets geprüfte, etablierte Bibliotheken und Algorithmen. Kryptografische Fehler können katastrophale Folgen haben und sind schwer zu erkennen.
Laden Sie Ihre aktuelle Verschlüsselungsarchitektur oder Konfigurationsdateien hoch, um eine Gap-Analyse gegenüber aktuellen kryptografischen Standards und Compliance-Anforderungen zu erhalten.
Neue Kryptografie-Entwicklungen
Post-Quantum-Kryptografie-Bereitschaft
Create post-quantum cryptography (PQC) transition plan for [organization]. Include:
- Kryptografie-Inventar (alle Systeme, die Public-Key-Krypto verwenden)
- Zeitplan und Risikobewertung der Quantenbedrohung
- Bewertung der NIST-PQC-Algorithmen (finalisierte Standards)
- Hybridansatz (klassisch + PQC während der Übergangsphase)
- Migrationsplan für die Zertifikatsinfrastruktur
- Anwendungs- und Protokoll-Updates (TLS 1.3 mit PQC)
- Zeitplan und Meilensteine (Krypto-Agilität jetzt, PQC-Migration bis [Datum])
- Kosten- und Aufwandsschätzung
- Testen und Validierung
- Koordination mit Anbietern und Partnern
Reference NIST SP 800-208, CNSA 2.0 timeline.Verwandte Prompts
- Siehe Infrastructure and cloud security prompts für Cloud-Verschlüsselungsimplementierungen
- Siehe Secure development lifecycle prompts für kryptografische Codierungsstandards
- Siehe Access control and identity management prompts für Authentifizierungsverschlüsselung