IT AI Skill

Encryption Key Management

Manage encryption keys, certificates, and cryptographic operations across infrastructure. Use when implementing encryption at rest/in transit, managing key rotation, deploying SSL/TLS certificates, maintaining HSM, enforcing encryption compliance, or managi...

Encryption & Key Management

Ensure comprehensive encryption coverage across all data stores and secure management of cryptographic keys and certificates.

Workflow

1. Encryption Assessment & Planning

  1. Encryption inventory and gap analysis:
  1. Encryption architecture design:
  1. Compliance requirements mapping:

2. Key Management Operations

  1. Key generation and storage:
  1. Key rotation lifecycle:
  1. Key backup and recovery:
  1. Key decommissioning:

3. Certificate Management

  1. Certificate inventory and lifecycle:
  1. Automated certificate provisioning:
  1. Certificate security standards:
  1. Internal PKI management:

4. Encryption Implementation

  1. Data at rest encryption:
  1. Data in transit encryption:
  1. Application-level encryption:
  1. Encryption monitoring and compliance:

5. Encryption Key Access Controls

  1. Access policy management:
  1. Emergency access procedures:

Templates & Frameworks

Key Rotation Schedule

KEY ROTATION CALENDAR — 2025
============================

Key Type           | Rotation Period | Next Rotation | Method
-------------------|----------------|---------------|------------------
Master Keys (HSM)  | Annual         | 2025-06-15    | Dual control
Data Enc Keys      | Quarterly      | 2025-07-01    | Automated wrap
TLS Certificates   | Per expiry     | Auto-renewal  | ACME/Let's Encrypt
DB TDE Keys        | Semi-annual    | 2025-09-01    | Zero-downtime
API Keys           | Monthly        | 2025-05-01    | Automated rotation
Customer Encrypt   | Per request    | As needed     | Application-managed
Backup Keys        | Annual         | 2025-11-01    | Offline ceremony

Certificate Expiry Monitoring

CERTIFICATE STATUS — April 2025
================================

EXPIRY RISK:
  🔴 Expiring < 7 days: 2 certificates (immediate action required)
     - api.example.com — expires Apr 22 — auto-renewal FAILED
     - internal-db.company.net — expires Apr 20 — manual renewal needed
  ⚠  Expiring < 30 days: 5 certificates (scheduled for renewal)
  ✓  Healthy (> 30 days): 127 certificates

CERTIFICATE COMPLIANCE:
  TLS 1.3 enabled: 89%
  Strong ciphers only: 94%
  OCSP stapling: 76%
  Certificate pinning (critical apps): 100%

Integration Points

Edge Cases

Output

Encryption Coverage Dashboard

ENCRYPTION STATUS — April 2025
===============================

ENCRYPTION COVERAGE:
  At Rest:  96% (47/49 systems encrypted)
  In Transit: 98% (148/151 connections encrypted)
  Endpoints: 100% (all 1,247 devices with FDE)
  Backups:  99% (all backup systems encrypted)

KEY MANAGEMENT:
  Total active keys: 342
  Keys past rotation date: 0 ✓
  HSM slots in use: 12/24
  Key backup integrity: Verified (last test: 2025-04-01)

CERTIFICATE MANAGEMENT:
  Total certificates: 134
  Auto-renewal configured: 118 (88%)
  Expiring this month: 5
  Non-compliant protocols: 8 (being remediated)

GAPS:
  🔴 2 unencrypted file shares — scheduled for encryption by April 25
  ⚠  8 systems using TLS 1.2 only (TLS 1.3 upgrade planned)

Trigger Phrases

"encryption", "key management", "certificate management", "TLS certificate", "key rotation", "HSM", "cryptographic keys", "encryption compliance", "encrypt data", "certificate expiry", "PKI", "TDE", "encryption at rest", "encryption in transit", "key backup", "certificate renewal", "mTLS", "key escrow"