A global logistics company uses BigQuery for analyzing shipment data. They have a dataset containing sensitive customer information that is classified as 'Confidential'. All access to this dataset must be logged, and any attempts by unauthorized users to access it should trigger an immediate alert to the security operations center (SOC). How should you implement this data governance policy?
- AUse BigQuery row-level security to prevent unauthorized access and set up an alert on BigQuery query job failures.
- BConfigure Cloud Audit Logs to log 'Data Access' events for the dataset and create a Cloud Logging sink to Pub/Sub, with a Cloud Function triggering an alert.
- CEncrypt the dataset with customer-managed encryption keys (CMEK) and monitor KMS key access logs.
- DGrant 'roles/bigquery.dataViewer' to authorized users and configure Cloud Monitoring alerts on BigQuery API errors.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure Cloud Audit Logs to log 'Data Access' events for the dataset and create a Cloud Logging sink to Pub/Sub, with a Cloud Function triggering an alert.
Cloud Audit Logs with 'Data Access' enabled will record all attempts to access the dataset, authorized or not. A Cloud Logging sink can then forward these logs to Pub/Sub, which can trigger a Cloud Function to parse the logs for unauthorized access attempts and send an immediate alert to the SOC.
Why the other options are wrong
- A. Row-level security prevents access but doesn't inherently provide the real-time alerting on *attempts* by unauthorized users. Alerting on query job failures is too broad and doesn't specify unauthorized access.
- C. CMEK encrypts the data, which is good for security, but monitoring KMS key access logs primarily tracks key usage, not attempts to access the BigQuery data itself by unauthorized users. CMEK doesn't replace the need for logging and alerting on data access attempts.
- D. Granting 'dataViewer' allows access, but merely alerting on 'API errors' won't specifically catch *unauthorized* access attempts that might still result in an error, nor does it provide the detailed logging needed for governance.
Cloud Audit Logs for Data Governance
Cloud Audit Logs record administrative activities and data access events across Google Cloud services. They are crucial for security, auditing, and compliance, enabling real-time monitoring and alerting on sensitive data access.
- Captures 'Admin Activity', 'Data Access', and 'System Event' logs.
- Data Access logs are disabled by default for BigQuery and need explicit enabling.
- Logs can be exported to Cloud Storage, BigQuery, or Pub/Sub via sinks.
- Essential for demonstrating compliance and detecting security incidents.
Memory trick: Audit Logs flow to Pub/Sub, then a Function calls the SOC club!