Professional Data EngineerEnsuring solution qualityHard
A global media company uses Google Cloud for its data analytics platform. They have multiple BigQuery datasets across different regions, each containing sensitive user data. To comply with GDPR, CCPA, and other regional regulations, they need to ensure that data access is strictly controlled based on the user's role and their need-to-know, regardless of the dataset's physical location. Specifically, they want to restrict access to certain columns (e.g., email addresses) for specific user groups, while allowing them to view other columns in the same table. Which BigQuery security feature should be implemented to achieve this granular control?
- AAuthorized Views
- BDataset-level IAM policies
- CData encryption with Customer-Managed Encryption Keys (CMEK)
- DColumn-level security
Show answer & explanationAnswer & explanation
Correct answer: D. Column-level security
Column-level security in BigQuery allows fine-grained access control to specific columns within a table, enabling the restriction of sensitive data like email addresses for certain user groups while allowing access to other columns, directly addressing the requirement for granular access based on need-to-know.
Why the other options are wrong
- A. Authorized Views can restrict access to rows or a subset of columns but require creating a separate view for each access pattern, which can become complex. Column-level security is more direct for column restriction.
- B. Dataset-level IAM policies control access to entire datasets or tables, not individual columns within a table.
- C. CMEK protects data at rest through encryption but does not provide granular access control to specific columns based on user roles.
BigQuery Column-level Security
BigQuery Column-level Security provides fine-grained access control to specific columns within a table, allowing you to restrict sensitive data based on user roles or groups.
- Uses Data Catalog policies to define access.
- Integrates with IAM for user/group permissions.
- Enables 'need-to-know' access for sensitive data.
- Applies to columns, allowing users to see other non-restricted columns in the same table.
Memory trick: Columns have secrets; give keys to only those who need them.