A global e-commerce company uses BigQuery for its analytics platform. They have sensitive customer data, including payment card information, which must be protected according to PCI DSS. While the data is stored securely, analysts need to query this data for aggregate reporting. The company wants to ensure that raw payment card numbers are never directly visible to analysts, even if they have access to the tables, but other fields in the same table should be accessible. How should the company implement this data access control?
- AApply data masking to the payment card information column in the relevant BigQuery tables.
- BCreate an authorized view that selects all columns except the payment card information.
- CUse BigQuery column-level security to restrict access to the payment card information column.
- DEncrypt the payment card information at the client-side before loading into BigQuery.
Show answer & explanationAnswer & explanation
Correct answer: A. Apply data masking to the payment card information column in the relevant BigQuery tables.
Data masking is the ideal solution here. It allows data in specific columns to be obfuscated or partially revealed based on the user's role, while still allowing queries on the underlying data. This meets the requirement that raw payment card numbers are never directly visible but aggregate reporting is still possible.
Why the other options are wrong
- B. An authorized view that excludes a column would prevent any analysis on that column, even aggregate, which might not meet the 'aggregate reporting' need.
- C. Column-level security completely restricts access to a column, preventing analysts from querying it at all, even for aggregate functions, which goes beyond the requirement.
- D. Client-side encryption would make it difficult for BigQuery to perform aggregate functions on the encrypted data without decryption, which defeats the purpose of hiding the raw value from analysts.
BigQuery Data Masking
BigQuery data masking allows you to selectively obfuscate or redact sensitive data in a column based on a user's role or identity. It enables data consumers to query the underlying data while protecting the raw sensitive values, which is crucial for compliance and privacy.
- Transforms data dynamically at query time.
- Allows different levels of masking based on user roles (e.g., full mask, partial mask).
- Protects sensitive data while still enabling analytics on the masked or aggregated data.
- Applied at the column level within BigQuery.
Memory trick: Mask the data, but let the numbers still play (in aggregates).