How BMO improved data security with Amazon Redshift and AWS Lake Formation
Big Data Blog
This article describes how BMO (Bank of Montreal) implemented robust data security controls for sensitive customer data in their Amazon Redshift data warehouse and Amazon S3 data lake using AWS Lake Formation and Amazon Redshift role-based access control (RBAC).
Specifically, the article covers:
- BMO's use case for securing sensitive financial data classified as Personally Identifiable Information (PII), Payment Card Industry (PCI) data, and High Privacy Risk (HPR) data
- The solution architecture using Amazon Redshift RBAC, AWS Lake Formation tag-based access control (TBAC), and integration with an external identity provider (IdP)
- Detailed step-by-step implementation walkthrough using synthetic data
- BMO's automated access provisioning framework using AWS Lambda, Amazon SQS, and Data API
- Benefits of the consolidated RBAC model based on data classification for streamlining access management while ensuring robust data security and compliance
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Feb 15
2024
2024
Simplify access management with Amazon Redshift and AWS Lake Formation for users in an External Identity Provider
Feb 16
2024
2024
Enhance data security and governance for Amazon Redshift Spectrum with VPC endpoints
Mar 4
2024
2024
Data Tokenization with Amazon Redshift Dynamic Data Masking and Protegrity
Jan 29
2024
2024
Data masking and granular access control using Amazon Macie and AWS Lake Formation
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.