A global manufacturing company uses BigQuery for its operational analytics. They have several datasets containing sensitive production data, including intellectual property (IP) related to product designs. They need to ensure that only specific engineering teams can view the 'design_specifications' column in the `production_designs` table, while other teams can still access other columns in the same table for general reporting. How should they implement this granular access control?
- AImplement BigQuery column-level security using policy tags on the 'design_specifications' column.
- BApply BigQuery data masking to the 'design_specifications' column to hide its content from unauthorized users.
- CCreate an authorized view that includes all columns except 'design_specifications' for general users.
- DStore 'design_specifications' in a separate table and restrict access to that table using Cloud IAM.
Show answer & explanationAnswer & explanation
Correct answer: A. Implement BigQuery column-level security using policy tags on the 'design_specifications' column.
BigQuery column-level security, implemented with policy tags, is designed precisely for this scenario. It allows you to restrict access to specific columns within a table based on user roles, ensuring that only authorized users (e.g., specific engineering teams) can view the sensitive column while others can still access the rest of the table.
Why the other options are wrong
- B. Data masking obfuscates the content but still allows the column to be queried (e.g., for aggregates), which might not be strong enough if the requirement is to *prevent viewing* the raw content.
- C. An authorized view that excludes the column prevents *any* access to it, even by authorized teams, and requires creating multiple views for different access levels.
- D. Storing sensitive columns in a separate table adds complexity, requires managing joins, and can impact query performance, making it a less ideal solution compared to native column-level security.
BigQuery Column-level Security
BigQuery column-level security allows you to define fine-grained access control on specific columns within a table. By assigning policy tags to columns and granting users access to these tags, you can restrict who can view or query the data in those sensitive columns.
- Restricts access to entire columns, not just their masked values.
- Uses policy tags to categorize and control access to sensitive columns.
- Integrated with Cloud IAM for granting access to policy tags.
- Allows different teams to access different subsets of columns in the same table.
Memory trick: Column Security: Tag the column, lock the view.