Professional Data EngineerManaging and securing dataHard

A global logistics company uses BigQuery for analyzing shipment data. They have a dataset containing sensitive customer addresses and shipment contents. To comply with GDPR, they need to ensure that access to this dataset is strictly controlled and all access attempts, successful or not, are logged with details about the user and the specific columns or rows accessed. Furthermore, they need to be able to trace who accessed what data for audit purposes. How should they implement this comprehensive data governance and auditing solution?

  1. AImplement BigQuery row-level security and column-level security and regularly export BigQuery `INFORMATION_SCHEMA` logs.
  2. BCreate authorized views for different user groups and rely on BigQuery job history for auditing.
  3. CEncrypt the sensitive fields using client-side encryption and store decryption keys in Cloud KMS.
  4. DConfigure Cloud IAM roles for fine-grained access to datasets and tables, and enable Data Access audit logs in Cloud Audit Logs for BigQuery.
Show answer & explanation

Correct answer: D. Configure Cloud IAM roles for fine-grained access to datasets and tables, and enable Data Access audit logs in Cloud Audit Logs for BigQuery.

Cloud IAM provides the fundamental access control (who can do what). Coupled with Cloud Audit Logs, specifically Data Access audit logs for BigQuery, this solution captures all access attempts (successful or denied), user identity, and details of the data accessed (including columns/rows, implicitly via query text). This combination directly addresses the 'strictly controlled' and 'all access attempts...logged with details' requirements for GDPR compliance and auditing.

Why the other options are wrong

  • A. While row-level and column-level security are good for access control, `INFORMATION_SCHEMA` does not provide comprehensive audit logs of all access attempts and specific data accessed for auditing.
  • B. Authorized views are good for restricting data exposure, but BigQuery job history alone does not provide the granular, detailed audit trail of *all* access attempts (including denied ones) or specific columns/rows accessed that Cloud Audit Logs provides.
  • C. Client-side encryption helps with data at rest and in transit, but it doesn't provide the auditing mechanism for who accessed what data *within BigQuery* for compliance purposes.

Cloud IAM and Cloud Audit Logs for Data Governance

Cloud IAM defines who has access to which Google Cloud resources and what actions they can perform. Cloud Audit Logs, particularly Data Access logs, record data access attempts, providing a comprehensive audit trail of user activities on data, which together form a robust solution for data governance, security, and compliance.

  • IAM specifies permissions (e.g., BigQuery Data Viewer, BigQuery Data Editor).
  • Cloud Audit Logs record administrative, system, and data access events.
  • Data Access logs capture detailed user activity on data, including queries.
  • Essential for meeting compliance standards like GDPR and HIPAA.

Memory trick: IAM sets the rules, Audit Logs watch the game.

More Managing and securing data questions