Professional Data EngineerManaging and securing dataMedium

A global media company uses BigQuery for analyzing user engagement data. They want to ensure that all queries accessing sensitive user demographic information (e.g., age, gender) are logged, including the user who ran the query, the query text, and the specific columns accessed. This information is crucial for their internal auditing and compliance requirements. How should they configure BigQuery to meet this logging requirement?

  1. AEnable Cloud Audit Logs for BigQuery and ensure Data Access audit logs are configured.
  2. BImplement BigQuery column-level security policies and monitor access through Cloud Audit Logs.
  3. CEnable Stackdriver Logging for BigQuery and configure Log Sinks to export to Cloud Storage.
  4. DUtilize BigQuery's built-in `INFORMATION_SCHEMA` views to query log data.
Show answer & explanation

Correct answer: A. Enable Cloud Audit Logs for BigQuery and ensure Data Access audit logs are configured.

Cloud Audit Logs, specifically Data Access audit logs, provide detailed information about API calls that read or modify data, including BigQuery query text, the user, and the resources (tables/columns) accessed. This directly addresses the requirement for auditing sensitive data access.

Why the other options are wrong

  • B. Column-level security controls access but doesn't inherently log *who* accessed *what* at the column level for auditing purposes; Cloud Audit Logs are still needed for the audit trail.
  • C. Stackdriver Logging (now Cloud Logging) is the general logging service, but specific configuration for Data Access logs is needed, and exporting to Cloud Storage alone doesn't guarantee content.
  • D. BigQuery `INFORMATION_SCHEMA` views primarily provide metadata about datasets, tables, and jobs, not detailed audit trails of data access at the column level by specific users.

Cloud Audit Logs for BigQuery Data Access

Cloud Audit Logs record administrative activities, system events, and data access on Google Cloud. For BigQuery, enabling Data Access logs captures detailed information about queries, including who ran them, the query text, and the resources (tables/columns) accessed, crucial for auditing and compliance.

  • Records API calls that read or modify data.
  • Captures user identity, operation, and affected resources.
  • Essential for security, auditing, and compliance.
  • Data Access logs are usually disabled by default for BigQuery and need explicit activation.

Memory trick: To know *who* touched *what* data, *audit* the *access*.

More Managing and securing data questions