Summary of BigQuery data security and governance features

This document gives a summary of the data security and governance features available in BigQuery.

All data security and governance features

Concepts and overviews

Description Documentation
Architecture, hierarchy of resources, and data governance
Google Cloud architecture framework
Google Cloud's Architecture Framework describes best practices, makes implementation recommendations, and goes into detail about products and services. The framework aims to help you design your Google Cloud deployment so that it best matches your business needs.
Architecture framework
Organizing BigQuery resources
Like other Google Cloud services, BigQuery resources are organized in a hierarchy. Your BigQuery resource hierarchy is fundamental for data governance in your BigQuery deployment.
Organizing BigQuery resources
Introduction to data governance
This document helps you understand the concept of data governance, and what controls you might need to secure your BigQuery resources.
Introduction to data governance

Securing resources with Identity and Access Management (IAM)

Description Documentation
IAM
Overview of IAM
IAM lets you grant granular access to specific Google Cloud resources and helps prevent access to other resources. IAM lets you adopt the security principle of least privilege, which states that nobody should have more permissions than they actually need.
Overview of IAM
Using resource hierarchy for access control
You can set IAM policies at different levels of the resource hierarchy. Resources inherit the policies of the parent resource. The resulting policy for a resource is the union of the policy set at that resource and the policy inherited from its parent.
Using resource hierarchy for access control
Access control roles and permissions
Predefined IAM roles and permissions in BigQuery
When an identity calls a Google Cloud API, the identity must have the appropriate permissions to use the resource. You can grant permissions by granting roles to a user, a group, or a service account. This page describes the BigQuery IAM roles that you can grant to identities to access BigQuery resources.
Predefined roles and permissions
Basic roles and permissions in BigQuery
BigQuery's dataset-level basic roles existed prior to the introduction of IAM. We recommend that you minimize the use of basic roles, and use IAM roles instead.
Basic roles and permissions
Access control by resource level
Controlling access to datasets
Dataset-level permissions determine the users, groups, and service accounts allowed to access the tables, views, and table data in a specific dataset.
Controlling access to datasets
Introduction to controlling access to tables and views
BigQuery Table ACL lets you set table-level permissions on resources like tables and views. Table-level permissions determine the users, groups, and service accounts that can access a table or view.
Controlling access to tables and views
Access control by authorization
Creating authorized views
Giving a view access to a dataset is also known as creating an authorized view in BigQuery. An authorized view allows you to share query results with particular users and groups without giving them access to the underlying source data.
Creating authorized views
Creating authorized UDFs
An authorized UDF is a UDF that is authorized to access a particular dataset. The UDF can query tables in the dataset, even if the user who calls the UDF does not have access to those tables.
Creating authorized UDFs

Securing data with classification

Description Documentation
Column-level security
Introduction to BigQuery column-level security
BigQuery provides fine-grained access to sensitive columns using policy tags, or type-based classification, of data. Using BigQuery column-level security, you can create policies that check, at query time, whether a user has proper access.
Column-level security
Row-level security
Introduction to BigQuery row-level security
Row-level security extends the principle of least privilege by enabling fine-grained access control to a subset of data in a BigQuery table, by means of row-level access policies.
Row-level security

Data discovery

Description Documentation
Cloud data loss prevention (DLP)
Using Cloud DLP to scan BigQuery data
Cloud DLP is a fully managed service that lets Google Cloud customers identify and protect sensitive data at scale.
Using Cloud DLP to scan BigQuery data
Data Catalog
Using Data Catalog
Data Catalog interacts with Cloud Data Loss Prevention (DLP) to automatically identify sensitive data by using Cloud DLP's powerful auto-tagging mechanism.
Data Catalog overview
Using Data Catalog policy tags in BigQuery
Use policy tags to define access to your data, for example, when you use BigQuery column-level security.
Using policy tags in BigQuery

Encryption

Description Documentation
Encryption at rest
Encryption at rest in Google Cloud
Google uses several layers of encryption to protect customer data at rest in Google Cloud products.
Encryption at rest in Google Cloud
Encryption at rest in BigQuery
BigQuery automatically encrypts all data before it is written to disk. The data is automatically decrypted when read by an authorized user. By default, Google manages the key encryption keys used to protect your data.
Encryption at rest in BigQuery
Customer-managed encryption keys (CMEK)
CMEK for BigQuery: Cloud KMS
If you want to control encryption yourself, you can use customer-managed encryption keys (CMEK) for BigQuery. Instead of Google managing the key encryption keys that protect your data, you control and manage key encryption keys in Cloud KMS.
Protecting data with Cloud KMS keys

Monitoring, auditing, and logging

Description Documentation
Introduction to BigQuery monitoring
This document provides a high-level overview of the monitoring data that is available for BigQuery.
Introduction to BigQuery monitoring
Introduction to BigQuery Admin Resource Charts
BigQuery Admin Resource Charts let BigQuery administrators observe how their organization, folder, or reservation uses BigQuery slots and how their queries perform.
BigQuery Admin Resource Charts
Creating dashboards and alerts for BigQuery
This document describes how to create charts and alerts to monitor BigQuery resources using Cloud Monitoring.
Creating dashboards and alerts for BigQuery
Auditing policy tags
This document describes how to use Cloud Logging to audit activities related to policy tags.
Auditing policy tags
BigQuery audit logs overview and reference
This page provides details about BigQuery specific log information, and it demonstrates how to use BigQuery to analyze logged activity.
Audit logs overview