Chapter SevenData Lake Security
Besides making data querying easier, data lakes in fact lead to better security outcomes. Without a unified data store, all analysis occurs in many different places. These far‐flung data sources require individual logins, which are hard to track and maintain the appropriate levels of access. It's unclear who has access to what. It can be hard to redact sensitive information that should not be used in company analytics. In other words, different sources of data are hard to manage.
With all the data in one spot and in one common engine, a data lake makes managing permissions much simpler. Common warehouse solutions come with power IAM management tools in addition to ordinary database security features.
Likewise, data coming into the data lake is likely not yet clean, so sensitive information may still exist. A data lake gives your security specialists fine control over what data can and cannot be accessed.
Avoid extracting or loading sensitive data/columns; instead, configure these items within the ELT tools. Also, be mindful of who can access the data lake since more data is accessible than individual data sources initially.
Access in Central Place
To simplify the management of access across multiple data sources, we recommend removing access from specific tools (such as BI), then migrating all access management to the data lake. Limiting access from multiple sources to one lake cuts down on access requests and mishaps where people retain access ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access