Showroom by Speechbox

Securely Running Databricks on AWS GovCloud: A Deep Dive for Public Sector and Regulated Industries

Pal PatelPartner Solutions Architect, Amazon Web Services
AWS GovCloudDatabricksPublic SectorFedRampData SecurityComplianceUnity Catalog

In an era of escalating cyber threats and stringent data regulations, public sector organizations and highly regulated industries face immense pressure to secure their data workloads. This session explores how Databricks, running on AWS GovCloud, provides a robust and compliant environment designed to meet the most demanding security standards, including FedRamp High and DoD Impact Level 5.

The foundation of this secure ecosystem is AWS GovCloud, an infrastructure-as-a-service region specifically engineered for customers with strict compliance needs. Unlike commercial regions, GovCloud is an isolated environment, managed by vetted US citizens on US soil, ensuring data residency and access controls that meet federal government requirements. It supports critical authorizations such as FedRamp High, DoD SRG IL4/IL5, and NIST 800-53, addressing the protection of Controlled Unclassified Information (CUI) and personally identifiable data. This bicoastal architecture, separated by geographical features, also provides inherent resiliency against terrestrial events.

Databricks on AWS GovCloud significantly benefits from inheriting AWS's comprehensive security and compliance controls. For instance, achieving FedRamp High certification requires meeting 421 security controls, all of which AWS GovCloud inherently provides. This foundational security accelerates the authorization journey for partners like Databricks, enabling them to build solutions on an already hardened platform. The platform, currently in public preview, offers key features like Unity Catalog, Databricks SQL dashboards, and MLflow experiments, with continuous improvements planned for full General Availability.

Enhanced security features are paramount for GovCloud deployments. Databricks mandates customer-managed VPCs, giving organizations granular control over network configurations, lower privilege levels for Databricks IAM roles, and simplified integration with centralized networking. AWS PrivateLink further ensures that all data traffic, both frontend and backend, remains within the AWS network, bypassing the public internet. Data encryption is robustly handled through AWS Key Management Service (KMS) for data at rest and in transit, allowing customers to manage their own encryption keys. Additionally, the Enhanced Security and Compliance Module (ESM) is a mandatory add-on, providing hardened images, FIPS 140-2 validated encryption, and continuous vulnerability scanning.

Beyond security, Databricks on AWS GovCloud offers advanced data governance capabilities, notably through the Unity Catalog. This feature, currently exclusive to Databricks on AWS, provides complete data lineage, fine-grained access control, and secure data sharing across multiple workspaces or with third parties. It allows government agencies to securely share data, notebooks, models, and other assets. Coupled with Delta Live Tables, which declaratively manages data transformations and workflow orchestration, organizations can focus on data quality and insights rather than infrastructure. The process for onboarding to AWS GovCloud involves setting up a standard AWS account for billing, followed by direct engagement with Databricks, as marketplace offerings are not available for GovCloud.

With that we can confidently say that AWS is one of the most secured cloud provider.

- Pal Patel, Partner Solutions Architect, Amazon Web Services

More Articles