บทที่ 10: Security and Privacy
3 min readSecurity First Mindset
Security ต้องมาก่อน ทุกอย่าง — data engineers จัดการ sensitive data ทุกวัน "Security is the first thing a data engineer needs to think about in every aspect of their job"
People: จุดอ่อนที่สุด
- คนและ organizational structure คือ จุดอ่อนใหญ่ที่สุด ใน security
- สร้าง culture of security — ทุกคนต้องเข้าใจ responsibility ของตัวเอง
- อย่า ignore basic precautions — phishing, irresponsible actions
Processes: หลักการสำคัญ
| Principle | คำอธิบาย |
|---|---|
| Principle of Least Privilege | ให้ access เท่าที่จำเป็น แค่เวลาที่จำเป็น |
| Shared Responsibility Model | Cloud provider รับผิดชอบ security of cloud, user รับผิดชอบ in cloud |
| Backup & Recovery | 3-2-1 rule: 3 copies, 2 media, 1 offsite |
| Incident Response | เตรียม plan ไว้ — everything breaks all the time |
| Security Theater vs Security Habit | ระวัง compliance ผิวเผิน (ทำตาม SOC-2, ISO 27001 แค่ให้ผ่าน audit) — ของจริงต้องปลูกฝัง security เป็นนิสัยประจำวันของทีม ไม่ใช่ policy หนาๆ ที่ไม่มีใครอ่าน |
| Active Security | ไม่หยุดแค่ standard checklist — ต้อง research threats/vulnerabilities ที่เฉพาะเจาะจงกับระบบและ incentive ขององค์กรตัวเองอย่างต่อเนื่อง |
- Broken glass process: สำหรับข้อมูล sensitive ที่ต้อง retain แต่ควรเข้าถึงเฉพาะกรณีฉุกเฉิน — ต้องผ่าน emergency approval ก่อน แล้ว revoke access ทันทีเมื่อใช้งานเสร็จ (ใช้คู่กับ column/row/cell-level access control และ masking PII)
Technology: เครื่องมือที่ต้องใช้
- Encryption at rest — data ใน storage (full-disk encryption บน laptop, server-side encryption ใน DB/object storage/backup)
- Encryption in transit — data ระหว่างเคลื่อนที่ (TLS — Transport Layer Security) — หลีกเลี่ยง protocol เก่าอย่าง FTP ที่เสี่ยง man-in-the-middle attack
- IAM (Identity and Access Management — จัดการตัวตนและสิทธิ์): users, roles, policies, groups — กำหนดว่าใครเข้าถึงอะไรได้บ้าง
- Credential hygiene: ใช้ SSO (Single Sign-On) + MFA (Multi-Factor Authentication) แทน password ตรงๆ, เก็บ secrets ผ่าน secrets manager ห้าม hardcode ลง code/version control
- Network Security: VPC (Virtual Private Cloud — เครือข่ายส่วนตัวเสมือน), subnets, firewalls, private connections, whitelist เฉพาะ IP ที่จำเป็น — cloud โดยทั่วไปใกล้เคียง zero-trust (ทุก action ต้อง authenticate) ปลอดภัยกว่า hardened perimeter แบบ on-prem ดั้งเดิม
- Data Masking & Tokenization: ปกปิด sensitive data (PII — Personally Identifiable Information, ข้อมูลที่ระบุตัวตนได้ เช่น ชื่อ, ID, email)
Logging, Monitoring, and Alerting
ส่วนใหญ่กว่าจะรู้ตัวว่าโดน breach ก็สายไปแล้ว — ต้อง monitor แบบ automated ใน 4 ด้าน:
- Access: ใครเข้าถึงอะไร เมื่อไหร่ จากที่ไหน — มี pattern แปลกๆ หรือ user ใหม่ที่ไม่รู้จักไหม
- Resources: CPU/disk/memory/I/O ที่เปลี่ยนแปลงผิดปกติอาจบ่งบอก breach
- Billing: cost spike กะทันหันอาจแปลว่ามีคนใช้ resource ไปในทางที่ผิด
- Excess permissions: permission ที่ไม่ได้ใช้นาน (เช่น ไม่ login เข้า Redshift 6 เดือน) ควรถูก revoke อัตโนมัติเพื่อลด attack surface
ควรมี dashboard รวมให้ทั้งทีมเห็น ผูกกับ incident response plan และซ้อมแผนอย่างสม่ำเสมอ
Compliance & Regulations
| Regulation | ข้อกำหนด |
|---|---|
| FERPA (Family Educational Rights and Privacy Act) | กฎหมายคุ้มครองข้อมูลการศึกษาของสหรัฐฯ (1970s) — หนึ่งใน privacy law ฉบับแรกๆ ที่วางรากฐานให้ฉบับหลังๆ |
| GDPR (General Data Protection Regulation) | กฎหมายคุ้มครองข้อมูลส่วนบุคคลของ EU — Right to be forgotten (สิทธิถูกลบ), data portability (ย้ายข้อมูลไปที่อื่นได้), consent (ต้องขออนุญาต) |
| CCPA (California Consumer Privacy Act) | กฎหมายคุ้มครองข้อมูลของ California — คล้าย GDPR |
| HIPAA (Health Insurance Portability and Accountability Act) | กฎหมายคุ้มครองข้อมูลสุขภาพของสหรัฐฯ |
| PCI DSS (Payment Card Industry Data Security Standard) | มาตรฐานความปลอดภัยข้อมูลบัตรเครดิต |
Internal Security Research
องค์กรควรมีโปรแกรมให้ engineers หา security bugs — incentive เพื่อให้คนช่วยกันหา vulnerabilities ก่อนผู้ไม่หวังดีจะ exploit