4 ms·
You can't prevent access but you can log all access and require a written reason for access. That, followed up by routine audits of access logs will reduce and
by gresrun 9y ago
You can't prevent access but you can log all access and require a written reason for access. That, followed up by routine audits of access logs will reduce and discourage abuse as described in the article.
- cookiecaper 9y agoThis is about Redshift, Amazon's cloud-based data warehousing tool. Auditing and logging every individual access made by data analysts, engineers, and others making use of Redshift would make their jobs impossible. One day of queries would take weeks to audit and validate a legitimate use case for all the individual data that got touched, and if you're just going to say "oh they needed everyone's PII because it was a big analytical query like they do all day", you're back at square one. The reality is that some people are going to need wide-reaching access. You could monitor for certain problematic access patterns, like someone who is supposed to be doing primarily aggregate queries doing a lot of specific ones, and I'm sure that'd be a good thing to do, but to be honest there are probably much higher priorities since employees who need sensitive access are probably going to be able to avoid that type of detection.