i like everything you said except the idea of lumping in encryption. that should not happen by default, it should have its own boot option, not be a feature of a boot option. if you want to keep it simple, call it "enc" or something.
also it would be annoying if you could not sudo su. just ask for the root password before allowing it.