Security center overview

This document describes the BigQuery Security center in the Google Cloud console. You can use the Security center to analyze your organization's data security profiles, configure and manage row-level and column-level security policies, and manage data governance tags and policy tags.

Before you begin

To view information in the Security center, you need the following:

Enable the Dataplex API, if it is not already enabled.

Roles required to enable APIs

To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

Enable the API

Required roles

To get the permissions that you need to manage and monitor security settings from the BigQuery Security center page, ask your administrator to grant you the following IAM roles:

  • Browse and search resources on the Resources tab, and view data masking routines: BigQuery Metadata Viewer (roles/bigquery.metadataViewer) on the project
  • Manage row-level access policies, data policies (column-level security), and table and dataset security: BigQuery Security Admin (roles/bigquery.securityAdmin) on the project
  • Attach policy tags to columns:
  • Create and manage data policies without dataset ownership: BigQuery Data Policy Admin (roles/bigquerydatapolicy.admin) on the project
  • Run query jobs and view security insights (including INFORMATION_SCHEMA views): BigQuery Job User (roles/bigquery.jobUser) on the project
  • Manage data governance tags: Tag Administrator (roles/resourcemanager.tagAdmin) on the organization
  • Create and manage policy tag taxonomies: Policy Tag Admin (roles/datacatalog.categoryAdmin) on the taxonomy or organization
  • Query columns protected by policy tags: Fine-Grained Reader (roles/datacatalog.categoryFineGrainedReader) on the taxonomy or policy tag
  • Use Gemini Cloud Assist in the Security center: Gemini for Google Cloud User (roles/cloudaicompanion.user) on the project

For more information about granting roles, see Manage access to projects, folders, and organizations.

You might also be able to get the required permissions through custom roles or other predefined roles.

Resource selection and security profile analysis

The Resources tab in the Security center lets you search for datasets and tables within a BigQuery project, view attached security policies, and analyze the security profile of each resource.

Analyze a security profile with Gemini Cloud Assist

Gemini Cloud Assist in the Security center lets you review security settings, ask questions about your resources, and analyze the security profile of a dataset or table:

  1. In the Google Cloud console, go to the BigQuery page.

    Go to BigQuery

  2. In the navigation menu, click Governance, and then click Security center.

  3. Click the Resources tab.

  4. Hold the pointer over a dataset or table, and then click astrophotography_mode Show security profile.

Gemini Cloud Assist generates a summary of the resource's security profile, including attached row-level access policies, column-level data policies, and classification tags.

To ask questions about security findings, policies, and access controls, you can also use the Gemini Cloud Assist chat panel.

For more information, see Use Gemini Cloud Assist.

Search and filter resources

The Resources tab provides the following capabilities for locating resources and inspecting access controls:

  • Project scope: the Resources tab displays datasets and tables in the selected Google Cloud project.
  • Search and filter: click Filter to search for resources by dataset name, table name, or location.
  • Inspect attached policies: the Policies and Policy tags columns show whether access policies or tags are attached to each table. To view policy details, click the resource name. To create or modify policies for a selected resource, go to the Policy management tab.

Policy management

The Policy management tab in the Security center lets you configure and manage row-level access policies and column-level security policies for your tables.

You can configure column-level security policies in three ways:

  • Directly assigned data policies on columns
  • Data governance tag-based policies (Preview)
  • Policy tag-based policies

Row access policies

The Row access view displays all row-level access policies created for your resources. For each policy, you can view the policy name, table name, dataset name, and last modified date. You can edit, delete, or create policies directly from this view.

When creating a row-level access policy, you specify the following:

  • Policy name: a unique name for the policy.
  • Table search: enter the table name in the search field to locate and select the target table.
  • Schema view: review the table schema to verify available column names.
  • Filter predicate: enter a SQL filter condition that defines which rows are visible (for example, region = 'us-east1').
  • Principals: specify the users, groups, or domains to which the policy applies.

For more information, see Introduction to BigQuery row-level security.

Column security policies

The Column security view lets you manage column-level access control and data masking across your resources.

To view column security policies, you must first select a region from the Region list.

After you select a region, policies appear in three sections based on how they were created:

  • Policy tags: policies tied to Data Catalog taxonomy tags.
  • Data governance tags: policies tied to Resource Manager tags with purpose=DATA_GOVERNANCE (Preview).
  • Directly assigned data policies: data policies attached directly to table columns without tag intermediaries.

Policy impact metrics

For each policy, the table displays impact metrics showing the number of tables and columns affected by that policy. These metrics indicate how widely a policy is applied across your datasets, helping administrators evaluate the reach and sensitivity of a policy before updating or reassigning it.

Attach policies to multiple columns

To attach an existing policy to multiple columns across different tables and datasets, in the policy table, click Attach. This lets you apply consistent column-level access controls or data masking rules across your organization in a single action.

When you assign principals to a data policy, BigQuery grants them the Masked Reader role (roles/bigquerydatapolicy.maskedReader) on that policy. This role is the only predefined role that grants bigquery.dataPolicies.maskedGet, the permission required to read masked values in the protected columns. For more information, see Roles for querying masked data.

Depending on your access control requirements, see one of the following guides for detailed instructions about configuring policies:

Data governance tags and policy tags

Data governance tags and policy tags let you classify columns and apply access controls across BigQuery resources.

To manage tags in the Security center:

  1. In the Google Cloud console, go to the BigQuery page.

    Go to BigQuery

  2. In the navigation menu, click Governance, and then click Security center.

  3. Depending on the type of tag you want to manage, select one of the following tabs:

    • Data governance tags: click the Data governance tags tab to create Resource Manager tag keys (with purpose=DATA_GOVERNANCE) and define hierarchical tag values (Preview). To configure access permissions, click Manage access.
    • Policy tags: click the Policy tags tab, and then click Create taxonomy to create Data Catalog taxonomies and hierarchical policy tags. To configure access permissions, use the permissions panel.

After you create tag keys or taxonomies, you attach the tags to table columns to enforce column-level access control and data masking:

What's next