Data Engineering for Humans • Training 07
Article-Training • Modern Data Platform Series

Governance & Security

Control, Protect and Explain Data Across the Platform

Trusted data needs ownership, context, controlled access and protection.

Own → Catalog → Classify → Control → Protect → Audit → Comply → Improve
Data
→
Governance
→
Security
Owner
|
Access
|
Protection
8learning modules
24interactive practices
5rapid review questions
50%certificate threshold
Learning target
Build data platforms that are understandable, controlled, protected and auditable.
Practice progress0 / 24

Complete 12 of 24 practices (50%) and enter your name to unlock the Certificate of Participation.

MODULE 01
🏛️

Governance Foundations

Data governance defines how data is owned, described, protected, shared and managed. It connects technical controls with business accountability so teams can scale data without losing trust or control.

⚙️
Key idea

Governance is an operating model • Ownership must be explicit • Policies need enforceable controls

Core ideas

  • Define decision rights and responsibilities
  • Connect business policy to technical enforcement
  • Measure adoption and exceptions
Conceptual model
Governance = Ownership
           + Metadata
           + Policy
           + Controls
           + Accountability
✅

Good governance reduces ambiguity: people know who decides, what rules apply and how exceptions are handled.

Practice — 3 cases

Practice 1 / Práctica 1
What is the core purpose of data governance?
Practice 2 / Práctica 2
What makes a governance policy operational?
Practice 3 / Práctica 3
Which is a warning sign of weak governance?
MODULE 02
👥

Ownership & Stewardship

Ownership answers who is accountable for a dataset or domain. Stewardship turns that accountability into daily practice by maintaining definitions, quality expectations, access rules and issue resolution.

🧮
Key idea

Owners decide • Stewards maintain • Engineers implement controls • Consumers follow approved use

Core ideas

  • Assign owners to critical domains
  • Define stewardship responsibilities
  • Create escalation paths for unresolved issues
Conceptual model
Owner      → accountability
Steward    → definitions + quality
Engineer   → technical controls
Consumer   → approved use
✅

A dataset without an accountable owner becomes everyone’s problem and nobody’s responsibility.

Practice — 3 cases

Practice 4 / Práctica 4
Who is accountable for approving the business use of a critical dataset?
Practice 5 / Práctica 5
What is a typical data steward responsibility?
Practice 6 / Práctica 6
What should happen when ownership is unclear?
MODULE 03
🗂️

Catalog, Metadata & Classification

A data catalog helps people discover datasets and understand what they mean. Metadata, business definitions, sensitivity labels, owners and usage context turn raw tables into assets that can be understood and governed.

🐍
Key idea

Catalog for discovery • Metadata for context • Classification for protection • Definitions for consistency

Core ideas

  • Capture technical and business metadata
  • Classify sensitive data consistently
  • Keep definitions close to the data asset
Conceptual model
Dataset
  owner: Finance
  sensitivity: Confidential
  refresh: Daily
  definition: Approved revenue
✅

If users cannot discover, interpret or classify data, they cannot govern it consistently.

Practice — 3 cases

Practice 7 / Práctica 7
What is the main value of a data catalog?
Practice 8 / Práctica 8
Which metadata is most useful for governance?
Practice 9 / Práctica 9
Why classify sensitive data?
MODULE 04
🧭

Lineage & Auditability

Lineage explains where data came from, how it changed and where it is consumed. Auditability adds evidence of who accessed data, which changes occurred and whether controls were followed.

🧱
Key idea

Trace sources • Understand transformations • Identify consumers • Preserve evidence

Core ideas

  • Capture source-to-consumption lineage
  • Log important access and administrative changes
  • Use audit evidence for investigation and compliance
Conceptual model
Source → Ingest → Transform → Warehouse → BI
          logs       lineage       access audit
✅

Lineage tells you how data moved; audit logs tell you who did what and when.

Practice — 3 cases

Practice 10 / Práctica 10
What does data lineage primarily describe?
Practice 11 / Práctica 11
What is the purpose of audit logging?
Practice 12 / Práctica 12
Which question is lineage best suited to answer?
MODULE 05
🔐

RBAC & Least Privilege

Role-Based Access Control (RBAC) grants permissions through roles rather than ad-hoc individual access. Least privilege means users and services receive only the permissions needed for their responsibilities, and no more.

✨
Key idea

Roles simplify management • Least privilege limits exposure • Reviews remove stale access

Core ideas

  • Grant access by job function
  • Separate read, write and administrative roles
  • Review and revoke access regularly
Conceptual model
AnalystRole  → SELECT
EngineerRole → SELECT + WRITE
AdminRole    → ADMIN
Default      → DENY
✅

Start with no access, then grant only what the role requires.

Practice — 3 cases

Practice 13 / Práctica 13
What is the goal of least privilege?
Practice 14 / Práctica 14
Why use RBAC?
Practice 15 / Práctica 15
What should happen to access no longer needed?
MODULE 06
🕶️

Masking, Privacy & Sensitive Data

Sensitive data should be exposed only when necessary. Masking, tokenization, minimization and purpose-based access reduce risk while still allowing approved analytical and operational use.

⏱️
Key idea

Minimize exposure • Mask when full values are unnecessary • Match access to approved purpose

Core ideas

  • Identify sensitive fields
  • Use masking or tokenization when appropriate
  • Avoid copying sensitive data into unnecessary environments
Conceptual model
SSN: 123-45-6789
Masked: ***-**-6789
Purpose: approved support role only
✅

The safest sensitive value is often the one you never expose to users who do not need it.

Practice — 3 cases

Practice 16 / Práctica 16
When is data masking most useful?
Practice 17 / Práctica 17
What does data minimization mean?
Practice 18 / Práctica 18
Which practice increases sensitive-data risk?
MODULE 07
🛡️

Encryption, Secrets & Secure Transport

Encryption protects data at rest and in transit, while secrets management protects credentials, keys and tokens used by pipelines and applications. Hard-coded secrets and unencrypted transport create avoidable risk.

🧪
Key idea

Encrypt at rest • Encrypt in transit • Keep secrets outside code • Rotate credentials

Core ideas

  • Use TLS for data in transit
  • Use platform encryption for stored data
  • Store credentials in a secrets manager
Conceptual model
Code → secret reference
Vault → credential
TLS → encrypted transport
Storage → encrypted at rest
✅

Security controls should make the safe path the easy default, not an optional extra.

Practice — 3 cases

Practice 19 / Práctica 19
Where should pipeline passwords or API keys be stored?
Practice 20 / Práctica 20
What protects data moving across a network?
Practice 21 / Práctica 21
Which practice is unsafe?
MODULE 08
📜

Policy, Compliance & Security by Design

Policies and compliance requirements should be translated into concrete architecture and operating controls. Security by design means protection is built into the platform from the beginning rather than added after an incident.

🧭
Key idea

Translate policy into controls • Document exceptions • Audit effectiveness • Design security early

Core ideas

  • Map requirements to technical controls
  • Review exceptions and compensating controls
  • Test that controls operate as intended
Conceptual model
Requirement → Control → Evidence → Review
     ↓           ↓          ↓
   Owner      Enforcement   Audit
✅

Compliance is not a checkbox; it is evidence that defined controls are operating consistently.

Practice — 3 cases

Practice 22 / Práctica 22
What does security by design mean?
Practice 23 / Práctica 23
What is good compliance evidence?
Practice 24 / Práctica 24
How should a policy exception be handled?

Knowledge Check

Can you explain how governance and security work together to make data understandable, controlled, protected and auditable? Open each item after answering it in your own words. The 24 interactive practices above drive certificate progress.

Why is ownership a governance control?

Because a named owner creates accountability for definitions, access decisions, quality expectations and policy exceptions.

How do catalog and classification work together?

The catalog helps users discover and understand assets; classification identifies sensitivity so appropriate controls can be applied.

Why is least privilege important?

It limits the blast radius of mistakes, compromised accounts and unnecessary access.

What is the difference between masking and encryption?

Masking limits what users see; encryption protects the underlying data at rest or in transit.

What makes a governance program auditable?

Clear policies, assigned owners, enforceable controls, logs, reviews and evidence that exceptions were managed.

Governance & Security Decision Map

Match each governance or security need with the most appropriate control.

NeedStrong candidate
Clarify accountabilityData owner / steward
Help users discover trusted dataCatalog + metadata
Protect sensitive fields for broad audiencesMasking / tokenization
Standardize permissions by job functionRBAC
Protect credentials used by pipelinesSecrets manager
Prove who accessed or changed dataAudit logs

Certificate of Participation

Governance and security make scale sustainable. Ownership gives accountability, metadata gives context, RBAC limits exposure, masking and encryption protect sensitive information, and audit evidence shows whether controls actually worked.

0 / 24 • 0%

Production note

This training uses vendor-neutral governance and security concepts so the practices apply across SQL Server, cloud platforms, data warehouses, lakehouses and modern analytics stacks.