Data Mesh Governance / Policies / Security

Encryption at rest

Category: Security
Platform: Azure Databricks

Context

Our threat model is defined here [add link to your internal threat model]. Analytical data may contain sensitive data that needs to be protected from attackers.

Decision

We store analytical domain data and data products only on Storage Accounts (that have data at rest enabled by default).

We use Microsoft-managed encryption keys (MMK).

Consequences

Considered Alternatives

Automation