Compliance security profile
This page describes the compliance security profile, its compliance controls, and supported features. To enable the compliance security profile, see Configure enhanced security and compliance settings.
Compliance security profile overview
The compliance security profile enables additional monitoring, enforced instance types for inter-node encryption, a hardened compute image, and other features and controls on Databricks workspaces.
Enabling the compliance security profile is required if you use Databricks to process data that is regulated under the following compliance standards:
- C5
- CCCS Medium (Protected B)
- DoD IL5
- FedRAMP High
- FedRAMP Moderate
- HIPAA
- HITRUST
- Infosec Registered Assessors Program (IRAP)
- ISMAP
- Korean Financial Security Institute (K-FSI)
- PCI-DSS
- TISAX
- UK Cyber Essentials Plus
You can also select to enable the compliance security profile for its enhanced security features without conforming to a compliance standard.
If you enable this feature on any workspace, you are charged for the Enhanced Security and Compliance add-on as described on the pricing page.
- You are solely responsible for ensuring your own compliance with all applicable laws and regulations.
- You are solely responsible for ensuring that the compliance security profile and the appropriate compliance standards are configured before processing regulated data.
- If you add HIPAA, it is your responsibility before you process PHI data to have a BAA agreement with Databricks.
- For features that integrate with external systems, you are solely responsible for verifying that your configuration and use of the feature meet applicable compliance requirements.
- You are solely responsible for verifying that sensitive information is never entered in customer-defined input fields, such as workspace names, compute resource names, tags, job names, job run names, network names, credential names, storage account names, and Git repository IDs or URLs. These fields might be stored, processed, or accessed outside the compliance boundary.
Account-level Genie One does not aggregate data from workspaces that have the compliance security profile enabled. See Use Genie One.
Compliance security profile security enhancements
Security enhancements include:
-
A hardened operating system image that includes:
- A CIS Level 1 hardened image
- FIPS 140 validated encryption modules
-
Automatic cluster updates, ensuring clusters have the latest updates by periodically restarting them during configurable maintenance windows. See Automatic cluster update.
-
Enhanced security monitoring, which includes monitoring agents that generate reviewable logs. See Monitoring agents in Databricks compute plane images.
-
Enforced use of AWS Nitro instance types in clusters and Databricks SQL SQL warehouses.
-
All egress communication uses TLS 1.2 or higher, including communication with the metastore.
Supported preview features
Only the Public Preview, Private Preview, and Beta features listed in this section are supported for workspaces with the compliance security profile enabled. The compliance security profile does not support any other Public Preview, Private Preview, or Beta features.
The following table lists all supported Public Preview, Private Preview, and Beta features:
- Most features are available for all compliance standards with the compliance security profile enabled.
- Features marked with a specific compliance standard (such as "HIPAA only") are supported only for workspaces configured with that compliance standard.
- Features marked "Serverless" are only available on the serverless compute plane. For serverless availability by region and compliance standard, see the Regional support for features table on each compliance standard page.
Databricks Apps is generally available. However, to use Databricks Apps with the compliance security profile, a workspace admin must enable it in the Previews page. See Databricks Apps and Manage workspace-level previews.
Some features are not available on AWS GovCloud. See Unavailable features.
Feature | Status | Compute | Notes |
|---|---|---|---|
Public Preview | Standard and serverless | HIPAA only | |
Public Preview | Standard and serverless | HIPAA only | |
Public Preview | Serverless only | ||
Public Preview | Standard and serverless | HIPAA only | |
Public Preview | Serverless only | ||
Beta | Serverless only | ||
Public Preview | Standard and serverless | ||
Data governance hub | Private Preview | Standard and serverless | |
Public Preview | Standard and serverless | ||
Public Preview | Serverless only | ||
Public Preview | Standard and serverless | ||
Exclusive access | Private Preview | Standard and serverless | |
Public Preview | Serverless only | ||
Public Preview | Standard and serverless | ||
Beta | Standard and serverless | ||
Beta | Standard and serverless | ||
Public Preview | Serverless only | ||
Public Preview | Standard and serverless | ||
Public Preview | Serverless only | ||
Beta | Standard and serverless | ||
Public Preview | Standard and serverless | ||
Public Preview | Serverless only | ||
Serverless forecasting Python SDK | Private Preview | Serverless only | |
Beta | Standard and serverless | ||
Beta | Standard and serverless | ||
Public Preview | Standard and serverless | ||
Public Preview | Standard and serverless | ||
Public Preview | Standard and serverless | ||
Public Preview | Standard and serverless | ||
Public Preview | Standard and serverless | Legacy feature. See Account-level and workspace-level SCIM provisioning. |