Professional Data EngineerDesigning data processing systemsHard

A data engineering team is designing a new data pipeline for a multinational corporation. The pipeline will process sensitive customer data from various regions, and the data must remain within its geographical region of origin (data residency) to comply with local regulations. Additionally, all data at rest and in transit must be encrypted, and access to the data must be strictly controlled and auditable. Which combination of Google Cloud features and services best addresses these security, privacy, and compliance requirements?

  1. AUsing Cloud Storage with bucket policies, Cloud KMS for encryption, and Cloud Audit Logs for access tracking.
  2. BDeploying resources in specific Google Cloud regions, utilizing Customer-Managed Encryption Keys (CMEK) for data at rest, configuring IAM for granular access control, and enabling Cloud Audit Logs.
  3. CImplementing VPC Service Controls for network isolation, enabling default encryption for Cloud Storage, and relying on basic IAM roles.
  4. DStoring data in Cloud SQL with database-level encryption, using service accounts for access, and custom logging.
Show answer & explanation

Correct answer: B. Deploying resources in specific Google Cloud regions, utilizing Customer-Managed Encryption Keys (CMEK) for data at rest, configuring IAM for granular access control, and enabling Cloud Audit Logs.

To meet strict data residency, encryption, access control, and auditability: deploying resources in specific regions ensures data residency. CMEK provides strong control over encryption keys for data at rest. IAM offers granular, attribute-based access control. Cloud Audit Logs capture all administrative activities and data access, providing the necessary audit trail for compliance.

Why the other options are wrong

  • A. While Cloud Storage, KMS, and Audit Logs are relevant, this option doesn't explicitly mention deploying in specific regions for data residency or the enhanced control of CMEK for encryption keys, which is crucial for sensitive data.
  • C. VPC Service Controls enhance network security but don't directly address data residency or encryption key management. Default encryption is Google-managed; CMEK provides customer control. Basic IAM roles might not be granular enough for 'strictly controlled' access.
  • D. Cloud SQL is not suitable for all types of data. Database-level encryption is good, but custom logging is less comprehensive than Cloud Audit Logs, and service accounts alone might not provide the full granularity of IAM for all users/groups.

Data Residency, Encryption, Access Control, and Auditability

A comprehensive security and compliance strategy involving geographical data placement, cryptographic protection of data, precise control over who can access data, and detailed logs of all data interactions.

  • Data residency: data remains within specified geographic boundaries.
  • Encryption: data is protected at rest and in transit.
  • Access control: granular permissions dictate who can interact with data.
  • Auditability: all data access and administrative actions are logged.
  • Crucial for regulated industries (e.g., finance, healthcare).

Memory trick: To protect sensitive data, think of a secure vault: it has a specific location, strong locks, restricted access, and a complete logbook of every entry.

More Designing data processing systems questions