Trusted data needs ownership, context, controlled access and protection.
Complete 12 of 24 practices (50%) and enter your name to unlock the Certificate of Participation.
Data governance defines how data is owned, described, protected, shared and managed. It connects technical controls with business accountability so teams can scale data without losing trust or control.
Governance is an operating model • Ownership must be explicit • Policies need enforceable controls
Governance = Ownership
+ Metadata
+ Policy
+ Controls
+ AccountabilityGood governance reduces ambiguity: people know who decides, what rules apply and how exceptions are handled.
Ownership answers who is accountable for a dataset or domain. Stewardship turns that accountability into daily practice by maintaining definitions, quality expectations, access rules and issue resolution.
Owners decide • Stewards maintain • Engineers implement controls • Consumers follow approved use
Owner → accountability
Steward → definitions + quality
Engineer → technical controls
Consumer → approved useA dataset without an accountable owner becomes everyone’s problem and nobody’s responsibility.
A data catalog helps people discover datasets and understand what they mean. Metadata, business definitions, sensitivity labels, owners and usage context turn raw tables into assets that can be understood and governed.
Catalog for discovery • Metadata for context • Classification for protection • Definitions for consistency
Dataset
owner: Finance
sensitivity: Confidential
refresh: Daily
definition: Approved revenueIf users cannot discover, interpret or classify data, they cannot govern it consistently.
Lineage explains where data came from, how it changed and where it is consumed. Auditability adds evidence of who accessed data, which changes occurred and whether controls were followed.
Trace sources • Understand transformations • Identify consumers • Preserve evidence
Source → Ingest → Transform → Warehouse → BI
logs lineage access auditLineage tells you how data moved; audit logs tell you who did what and when.
Role-Based Access Control (RBAC) grants permissions through roles rather than ad-hoc individual access. Least privilege means users and services receive only the permissions needed for their responsibilities, and no more.
Roles simplify management • Least privilege limits exposure • Reviews remove stale access
AnalystRole → SELECT
EngineerRole → SELECT + WRITE
AdminRole → ADMIN
Default → DENYStart with no access, then grant only what the role requires.
Sensitive data should be exposed only when necessary. Masking, tokenization, minimization and purpose-based access reduce risk while still allowing approved analytical and operational use.
Minimize exposure • Mask when full values are unnecessary • Match access to approved purpose
SSN: 123-45-6789
Masked: ***-**-6789
Purpose: approved support role onlyThe safest sensitive value is often the one you never expose to users who do not need it.
Encryption protects data at rest and in transit, while secrets management protects credentials, keys and tokens used by pipelines and applications. Hard-coded secrets and unencrypted transport create avoidable risk.
Encrypt at rest • Encrypt in transit • Keep secrets outside code • Rotate credentials
Code → secret reference
Vault → credential
TLS → encrypted transport
Storage → encrypted at restSecurity controls should make the safe path the easy default, not an optional extra.
Policies and compliance requirements should be translated into concrete architecture and operating controls. Security by design means protection is built into the platform from the beginning rather than added after an incident.
Translate policy into controls • Document exceptions • Audit effectiveness • Design security early
Requirement → Control → Evidence → Review
↓ ↓ ↓
Owner Enforcement AuditCompliance is not a checkbox; it is evidence that defined controls are operating consistently.
Can you explain how governance and security work together to make data understandable, controlled, protected and auditable? Open each item after answering it in your own words. The 24 interactive practices above drive certificate progress.
Because a named owner creates accountability for definitions, access decisions, quality expectations and policy exceptions.
The catalog helps users discover and understand assets; classification identifies sensitivity so appropriate controls can be applied.
It limits the blast radius of mistakes, compromised accounts and unnecessary access.
Masking limits what users see; encryption protects the underlying data at rest or in transit.
Clear policies, assigned owners, enforceable controls, logs, reviews and evidence that exceptions were managed.
Match each governance or security need with the most appropriate control.
| Need | Strong candidate |
|---|---|
| Clarify accountability | Data owner / steward |
| Help users discover trusted data | Catalog + metadata |
| Protect sensitive fields for broad audiences | Masking / tokenization |
| Standardize permissions by job function | RBAC |
| Protect credentials used by pipelines | Secrets manager |
| Prove who accessed or changed data | Audit logs |
Governance and security make scale sustainable. Ownership gives accountability, metadata gives context, RBAC limits exposure, masking and encryption protect sensitive information, and audit evidence shows whether controls actually worked.
This training uses vendor-neutral governance and security concepts so the practices apply across SQL Server, cloud platforms, data warehouses, lakehouses and modern analytics stacks.