Professional Data EngineerManaging and securing dataMedium
A global manufacturing company uses BigQuery for its operational analytics. They have several datasets containing sensitive production data, including intellectual property details. The company needs to implement a solution that allows different teams to access specific subsets of columns within these tables based on their roles, without creating multiple copies of the data. For example, the R&D team needs to see all columns, while the sales team only needs product ID and quantity. Which BigQuery feature should be used to achieve this column-level access control efficiently?
- ABigQuery Authorized Views
- BBigQuery Column-level Security
- CBigQuery Data Masking
- DBigQuery Row-level Security
Show answer & explanationAnswer & explanation
Correct answer: B. BigQuery Column-level Security
BigQuery Column-level Security allows granular access control to specific columns within a table using policy tags without duplicating data. This directly addresses the requirement for different teams to see different subsets of columns based on their roles.
Why the other options are wrong
- A. Authorized Views restrict access to rows and columns through a view, but Column-level Security is designed for direct column access control without the overhead of creating numerous views.
- C. Data Masking obfuscates or anonymizes data, not restricts access to entire columns.
- D. Row-level Security restricts access to specific rows, not columns, within a table.
BigQuery Column-level Security
A BigQuery feature that allows granular access control to specific columns within a table, ensuring users only see data relevant to their roles.
- Uses Policy Tags to classify columns.
- Access is granted via Identity and Access Management (IAM) roles on Policy Tags.
- Does not require creating multiple views or data copies.
Memory trick: Columns have Tags, IAM grants access, so sensitive data stays hidden from prying eyes, but not from authorized ones.