Instiq
Chapter 4 · Data Security and Governance·v2.1.0·Updated 6/14/2026·~8 min

What's changed: In-scope coverage: added network boundary/defense (VPC/PrivateLink/WAF/Shield)

4.2Governance and Compliance (Lake Formation)

Key points

Understand data governance: fine-grained (column/row-level) access management with AWS Lake Formation, auditing with CloudTrail, and classification/data lineage with tags.

A data lake needs fine-grained control over who can access which columns/rows. AWS Lake Formation centralizes this.

4.2.1Lake Formation and auditing

Diagram showing AWS Lake Formation (central permissions for the lake, column/row/cell level, granted on Glue Catalog tables) and audit & lineage (CloudTrail for who accessed what, tags for classification, compliance and data lineage).
Fine-grained governance with Lake Formation
  • Lake Formation: centrally grant column/row/cell-level permissions on Glue Data Catalog tables.
  • CloudTrail: records who accessed/changed which data and when, for auditing.
  • Tags/lineage: classify data (e.g., sensitivity) and track origin/flow (data lineage).
Exam point

Common on DEA: column/row-level fine-grained access = Lake Formation, audit who accessed data = CloudTrail, classification = tags. Lake Formation centralizes permissions over the Glue catalog.

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.