Summary of BigQuery data security and governance features
This document gives a summary of the data security and governance features available in BigQuery.
All data security and governance features
Concepts and overviews
| Description | Documentation | |
|---|---|---|
| Architecture, hierarchy of resources, and data governance | ||
| Google Cloud architecture framework Google Cloud's Architecture Framework describes best practices, makes implementation recommendations, and goes into detail about products and services. The framework aims to help you design your Google Cloud deployment so that it best matches your business needs. |
Architecture framework | |
| Organizing BigQuery resources Like other Google Cloud services, BigQuery resources are organized in a hierarchy. Your BigQuery resource hierarchy is fundamental for data governance in your BigQuery deployment. |
Organizing BigQuery resources | |
| Introduction to data governance This document helps you understand the concept of data governance, and what controls you might need to secure your BigQuery resources. |
Introduction to data governance | |
Securing resources with Identity and Access Management (IAM)
| Description | Documentation | |
|---|---|---|
| IAM | ||
| Overview of IAM IAM lets you grant granular access to specific Google Cloud resources and helps prevent access to other resources. IAM lets you adopt the security principle of least privilege, which states that nobody should have more permissions than they actually need. |
Overview of IAM | |
| Using resource hierarchy for access control You can set IAM policies at different levels of the resource hierarchy. Resources inherit the policies of the parent resource. The resulting policy for a resource is the union of the policy set at that resource and the policy inherited from its parent. |
Using resource hierarchy for access control | |
| Access control roles and permissions | ||
| Predefined IAM roles and permissions in BigQuery When an identity calls a Google Cloud API, the identity must have the appropriate permissions to use the resource. You can grant permissions by granting roles to a user, a group, or a service account. This page describes the BigQuery IAM roles that you can grant to identities to access BigQuery resources. |
Predefined roles and permissions | |
| Basic roles and permissions in BigQuery BigQuery's dataset-level basic roles existed prior to the introduction of IAM. We recommend that you minimize the use of basic roles, and use IAM roles instead. |
Basic roles and permissions | |
| Access control by resource level | ||
| Controlling access to datasets Dataset-level permissions determine the users, groups, and service accounts allowed to access the tables, views, and table data in a specific dataset. |
Controlling access to datasets | |
| Introduction to controlling access to tables and views BigQuery Table ACL lets you set table-level permissions on resources like tables and views. Table-level permissions determine the users, groups, and service accounts that can access a table or view. |
Controlling access to tables and views | |
| Access control by authorization | ||
| Creating authorized views Giving a view access to a dataset is also known as creating an authorized view in BigQuery. An authorized view allows you to share query results with particular users and groups without giving them access to the underlying source data. |
Creating authorized views | |
| Creating authorized UDFs An authorized UDF is a UDF that is authorized to access a particular dataset. The UDF can query tables in the dataset, even if the user who calls the UDF does not have access to those tables. |
Creating authorized UDFs | |
Securing data with classification
| Description | Documentation | |
|---|---|---|
| Column-level security | ||
| Introduction to BigQuery column-level security BigQuery provides fine-grained access to sensitive columns using policy tags, or type-based classification, of data. Using BigQuery column-level security, you can create policies that check, at query time, whether a user has proper access. |
Column-level security | |
| Row-level security | ||
| Introduction to BigQuery row-level security Row-level security extends the principle of least privilege by enabling fine-grained access control to a subset of data in a BigQuery table, by means of row-level access policies. |
Row-level security | |
Data discovery
| Description | Documentation | |
|---|---|---|
| Cloud data loss prevention (DLP) | ||
| Using Cloud DLP to scan BigQuery data Cloud DLP is a fully managed service that lets Google Cloud customers identify and protect sensitive data at scale. |
Using Cloud DLP to scan BigQuery data | |
| Data Catalog | ||
| Using Data Catalog Data Catalog interacts with Cloud Data Loss Prevention (DLP) to automatically identify sensitive data by using Cloud DLP's powerful auto-tagging mechanism. |
Data Catalog overview | |
| Using Data Catalog policy tags in BigQuery Use policy tags to define access to your data, for example, when you use BigQuery column-level security. |
Using policy tags in BigQuery | |
Encryption
| Description | Documentation | |
|---|---|---|
| Encryption at rest | ||
| Encryption at rest in Google Cloud Google uses several layers of encryption to protect customer data at rest in Google Cloud products. |
Encryption at rest in Google Cloud | |
| Encryption at rest in BigQuery BigQuery automatically encrypts all data before it is written to disk. The data is automatically decrypted when read by an authorized user. By default, Google manages the key encryption keys used to protect your data. |
Encryption at rest in BigQuery | |
| Customer-managed encryption keys (CMEK) | ||
| CMEK for BigQuery: Cloud KMS If you want to control encryption yourself, you can use customer-managed encryption keys (CMEK) for BigQuery. Instead of Google managing the key encryption keys that protect your data, you control and manage key encryption keys in Cloud KMS. |
Protecting data with Cloud KMS keys | |
Monitoring, auditing, and logging
| Description | Documentation | |
|---|---|---|
| Introduction to BigQuery monitoring This document provides a high-level overview of the monitoring data that is available for BigQuery. |
Introduction to BigQuery monitoring | |
| Introduction to BigQuery Admin Resource Charts BigQuery Admin Resource Charts let BigQuery administrators observe how their organization, folder, or reservation uses BigQuery slots and how their queries perform. |
BigQuery Admin Resource Charts | |
| Creating dashboards and alerts for BigQuery This document describes how to create charts and alerts to monitor BigQuery resources using Cloud Monitoring. |
Creating dashboards and alerts for BigQuery | |
| Auditing policy tags This document describes how to use Cloud Logging to audit activities related to policy tags. |
Auditing policy tags | |
| BigQuery audit logs overview and reference This page provides details about BigQuery specific log information, and it demonstrates how to use BigQuery to analyze logged activity. |
Audit logs overview |

