data-protection-and-encryption
Installation
SKILL.md
Data protection and encryption
Perimeter and identity controls protect access to data. These controls protect the data when those have already failed, which is the scenario worth designing for.
Classify before you protect, because you cannot protect everything equally
A short scale beats a detailed one — three or four levels that people can apply without a manual. What matters is that each level carries concrete handling rules: where it may be stored, who may access it, whether it may leave the environment, and how long it is kept.
Find it before you classify it. Sensitive data is rarely only where the architecture says it is: it accumulates in exports, analytics environments, test databases seeded from production, support tickets, and log files.
Know what each kind of encryption actually defends against
This is where claims get made loosely and expectations diverge from reality.