Pretty Good Privacy (PGP)

Hybrid Encryption for Protecting Messages and Files

What is Pretty Good Privacy (PGP)?

Pretty Good Privacy encryption is a historically named technology for protecting data with hybrid Cryptography and Digital Signatures. For confidentiality, software generates a random symmetric session key to encrypt the content, then protects that session key for each recipient with public-key cryptography. For authenticity and integrity, Hashing produces a message digest that a sender signs with a private key and recipients verify with the corresponding public key. PGP refers to product history and an ecosystem; RFC 9580 defines the current OpenPGP message format for interoperable implementations. OpenPGP does not require certificate-authority trust. Users may validate keys through fingerprints, organizational processes, or decentralized trust relationships, each with different assurance and governance implications.

What is Pretty Good Privacy (PGP) used for?

PGP and OpenPGP implementations support encrypted email, protected files, software or package signatures, and integrity checks. Secure operation requires independent public-key fingerprint verification, protected private keys, strong passphrases or hardware storage, controlled subkeys, expiry, revocation certificates, and algorithm agility. Organizations must also decide whether recovery or escrow requirements justify additional access to encryption keys. Encryption protects content, not necessarily recipients, timing, subject lines, routing data, or compromised endpoints. Likewise, a mathematically valid signature proves control of a signing key and message integrity; it establishes a real-world identity only when the key-to-person binding has been verified. Data Loss Prevention (DLP) and Email Security Gateway (ESG) controls may complement protected messaging, but they do not replace endpoint and key governance.

Continue reading

Honeypot
Decoy System for Threat Detection
Packet Sniffing
Network Traffic Interception Technique
The Information Systems Audit and Control Association (ISACA)
IT Governance and Risk Organization

Please note!
Any use of this website requires prior agreement to our Terms of Use, Privacy Policy, and Cookie Policy.
If you do not fully agree to all of them, do not use this website.