---
title: >-
  BigQuery tables should be encrypted with customer-managed encryption keys
  (CMEK)
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BigQuery tables should be encrypted
  with customer-managed encryption keys (CMEK)
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BigQuery tables should be encrypted with customer-managed encryption keys (CMEK)
 
## Description{% #description %}

BigQuery tables stored in BigQuery-managed storage should use customer-managed encryption keys (CMEK) to provide control over key access and lifecycle. [Logical views](https://docs.cloud.google.com/bigquery/docs/views-intro) and [external tables](https://docs.cloud.google.com/bigquery/docs/external-tables) are excluded because they do not store data in BigQuery-managed storage. Google Cloud has published a [known issue](https://issuetracker.google.com/issues/212719457?pli=1) affecting access to the required BigQuery encryption field.

## Remediation{% #remediation %}

Follow [Customer-managed Cloud KMS keys](https://cloud.google.com/bigquery/docs/customer-managed-encryption) to copy existing table data using a customer-managed encryption key.
