Snowflake - Account Options & Assurances
Guidance Questions
- What are some industry compliance standards Snowflake has been certified in or awarded?
- Global:
- ISO-27001 - International Organization for Standardization, certificate for establishing, implementing, maintaining, and continually improving an information security management systems.
- ISO-27017 - 2015 version
- ISO-27018 - 2019 version
- SOC 1 Type II - independent auditor assessment of security controls.
- SOC 2 Type II - independent auditor assessment of security controls.
- U.S. Government:
- CJIS (Criminal Justice Information Services) - compliance for Public Sector customers, making sure they are in compliance with the FBI’s Criminal Justice Information Services (CJIS) Security Policy
- FedRAMP (Federal Risk and Authorization Management Program) - compliance for security standards for cloud technologies used by federal agencies.
- ITAR (International Traffic in Arms Regulations) - compliance standard for companies in the defense sector, which controls and restricts access to and export of military and defense articles, services and related technologies.
- Companies which require ITAR compliance must purchase Business Critical edition or higher.
- Only available with vetted providers, employees and contractors in SnowGov regions.
- StateRAMP - is a 501(c)6 nonprofit that offers cloud security certifications for:
- State and local government.
- Public education institutions.
- Special districts.
- Healthcare and Life Science:
- HITRUST CSF (Health Information trust Alliance Common Security Framework) - serves to unify security standards based on US federal law (HIPPA & HITECH), state specific laws and other industry standards into a single comprehensive standard for information security in the healthcare industry.
- Regulatory Compliance:
- PCI-DSS (Payment Card Industry Data Security Standards) - security standard for merchants, service providers and financial institutions building and deploying payment solutions and products.
- Regional -- Australia:
- IRAP (Protected) (Infosec Registered Assessors Program) - is a programs governed by the Australian Signals Directorate (ASD) which aims to certify cyber security professionals to provide relevant services to Australian Government and industry.
- Source)
- What choices are available when choosing a cloud platform provider for your Snowflake account?
- Amazon Web Services (AWS).
- Microsoft Azure (Azure).
- Google Cloud Services (GCP).
- Source
- What are regions and availability zones and how are they affected by your choice of a cloud platform provider?
- Regions are geographical subdivisions where data centers are physically located, you can choose regions to fit your compliance, latency and cost needs.
- The available regions are determined by the cloud platform provider.
- Source
- What are the benefits for moving from Snowflake's Standard Edition to Enterprise? What are the benefits for moving from Enterprise to Business Critical?
- Standard to Enterprise:
- 90 Time Travel.
- Rekeying.
- Row and Column level security.
- Object tagging.
- Classifying sensitive data.
- Auditing user access history.
- Query acceleration - parallel processing portions of eligible queries.
- Search Optimization - point lookup queries with automatic maintenance.
- Materialized Views - with automatic maintenance of results.
- Enterprise to Business Critical:
- Failover and failback between snowflake accounts for business continuity and disaster recovery.
- Redirecting Client Connections between Snowflake accounts for business continuity and disaster recovery.
- Tri-Secret Secure.
- Support for Private Connections.
- Support for internal Private Link(AWS&Azure).
- PHI DSS compliance and support.
- FedRAMP compliance and support.
- ITAR compliance and support.
- IRAP compliance and support.
- HIPAA and HITRUST CSF compliance and support.
- What factors should be considered when choosing the Geographic Region for your account?
- Infrastructure available in the region (AWS, Azure, GCP).
- Region of the point of service (to reduce latency).
- Number of availability zones within a region.
- Compliance, as in being required to host data in a certain jurisdiction.
- Source
Quiz:
- Is Snowflake HIPPA compliant?
- Yes
- What are the names of the three Snowflake Editions offered when signing up for a trail account?
- Standard, Enterprise, Business Critical.
- Which Snowflake Editions automatically store data in an encrypted state?
- Standard, Enterprise, Business Critical.
- Which of the following industry compliance standards has Snowflake been audited and certified for?
- SOC 1
- SOC Type 2
- PCI DSS
- FedRAMP
- HIPPA
- What setting up a new Snowflake Account, what steps or choices must the enrollee complete?
- Choose a Cloud Infrastructure Provider
- Choose a Snowflake Edition
- Choose a Geographic Deployment Region
- Which cloud infrastructure providers are available as the cloud platform for Snowflake Accounts?
- AWS
- Azure
- Google Cloud Platform (GCP)
- When signing up for a new Snowflake Account, enrolles first choose a cloud infrastructure provider and then a region. When choosing Azure, an enrollee might then choose the "Australia East" region. When choosing AWS, the "Australia East" region is not listed. Instead, a region called "Asia Pacific (Sydney)" is listed. Why?
- each cloud provider maintains its own regions and names the regions as they see fit.
- When choosing a geographic deployment region, what factors might an enrollee consider?
- Proximity to the point of service.
- Number of availability zones within a region.
- The following questions have to do cloud platforms. Select all the statements that are true.
- A company can use more than one cloud infrastructure provider by setting up several Snowflake accounts.
- A company can have its data stored in more than one geographical region by setting up several Snowflake account.
- A company can use a combination of data sharing and replication to distribute data to various regions and cloud platforms.