Security and Compliance¶
Security practices for data teams.
For the full framework, see → Security Excellence
Data Access and Governance¶
- Mask sensitive fields in dev and UAT environments
- Limit production data access to approved users only
- Access should be role-based and reviewed periodically
Secrets Management¶
- Never hardcode credentials in code or configuration files
- Use pipeline secret stores or a vault solution
- Rotate credentials regularly
Dependency Management¶
- Run automated vulnerability scanning in CI
- Review and update dependencies regularly
- Track known vulnerabilities and have a defined response process