ArcGIS Cloud Security: How to Protect Your GIS Data in the Cloud
GIS teams now run most of their maps, layers, and location data through the cloud. This makes work faster and easier to share. But it also raises a real question: who keeps that data safe? ArcGIS cloud security is not something Esri handles alone, and it is not something your IT team handles alone either. It is shared work.
This guide breaks down how ArcGIS cloud security actually works, what Esri and your cloud provider protect by default, and what your organization still needs to manage. You will find a clear checklist, backup guidance, and answers to common questions about GIS data security.
Whether you run ArcGIS Online, ArcGIS Enterprise, or a mix of both, this guide will help you protect your data without guesswork or fear based claims. Let’s start with the basics.
Is ArcGIS Secure in the Cloud?
Yes, ArcGIS is built with strong security from the ground up. Esri uses encryption, secure data centers, and strict access controls to protect every layer of the platform, from ArcGIS Online to ArcGIS Enterprise.
But ArcGIS cloud security is not just about Esri’s side. Your organization still controls who can see, edit, or share your maps and data. Real GIS data security depends on both sides doing their part well.
Understanding the Shared Responsibility Model for ArcGIS
Cloud security only works when everyone knows their job. The ArcGIS shared responsibility model splits duties among four groups. Below are the roles each group plays in keeping your ArcGIS cloud security strong, from data centers to daily user permissions.
-
Esri
Esri builds and maintains the ArcGIS platform itself. This includes patching software, encrypting data in transit and at rest, running background checks on staff, and meeting standards like FedRAMP Moderate for United States government customers using ArcGIS Online security features.
-
AWS or Microsoft Azure
ArcGIS Online and many ArcGIS Enterprise cloud deployments run on AWS or Microsoft Azure. These providers secure the physical data centers, servers, and core network hardware. This is called security of the cloud, and it forms the foundation under every layer of cloud GIS security.
-
The Customer Organization
Your organization controls user accounts, sharing settings, and content permissions. This is security in the cloud. Weak passwords, over shared maps, or unused accounts create most real world GIS data security problems, even when the platform itself is fully protected.
-
A Managed Services or Security Partner
Many organizations bring in a managed ArcGIS cloud services partner to monitor accounts, manage backups, and respond to alerts. This adds a trained team watching your environment daily, which helps close gaps that internal staff may not have time to catch.
Responsibility matrix at a glance:
| Area | Esri | Cloud Provider | Customer | Managed Partner |
| Data center physical security | Full | Full | None | Reviews reports |
| Platform patching | Full | Infrastructure only | None | Optional oversight |
| Data encryption | Default in transit and at rest | Underlying infrastructure | Extra encryption if needed | Verifies settings |
| User accounts and roles | None | None | Full | Monitors and audits |
| Backup and recovery | Platform redundancy | Infrastructure redundancy | Backup planning | Full management option |
| FedRAMP authorizations for secure cloud services increased by 60% between 2019 and 2023, strengthening cloud security standards for platforms such as ArcGIS Online used by government agencies. | ||||||
What Is Protected by Default and What Is Not?
Not every part of ArcGIS cloud security is automatic. Some protections come built in, while others depend entirely on how your team sets things up. Below are the main areas where default protection ends and your own security choices begin.
-
Encryption in Transit and at Rest
ArcGIS Online encrypts data moving between users and servers using TLS 1.2 or newer. Stored data uses AES 256 bit encryption or better. This GIS data encryption happens automatically, but customer supplied secrets and integrations still need careful configuration by your team.
-
Platform and Infrastructure Security
Esri and its cloud providers patch servers, monitor networks, and run background checks on staff. This layer is protected by default and applies to both ArcGIS Online and ArcGIS Enterprise security configurations. Your organization does not manage servers directly, but should still confirm these protections through Esri’s trust documentation each year.
-
Identity, Accounts, and User Roles
ArcGIS identity and access management is not automatic. Your organization must assign roles, remove old accounts, and require strong sign in methods like SAML or multi factor authentication. Left unmanaged, this is the most common cause of ArcGIS Online security gaps.
-
Sharing and Content Permissions
By default, new items in ArcGIS Online are private. But once a map or layer is shared publicly or with a large group, that setting stays until someone changes it. Regular sharing reviews are key to protecting GIS data in the cloud.
-
Network and Application Security
Application level protections, like securing an ArcGIS utility network deployment or a public facing web map, often need extra firewall rules and authentication layers. These are not always covered by default settings and need direct attention from your GIS or IT team.
A Practical ArcGIS Cloud Security Checklist
Turning ArcGIS cloud security into daily habits is easier with a clear list. Use this ArcGIS cloud security checklist as a starting point, then adjust it based on your data sensitivity, team size, and whether you support utility asset data management or public services.
- Turn on multi factor authentication for every account.
- Review sharing settings on maps and layers every quarter.
- Remove unused or inactive user accounts right away.
- Encrypt sensitive data before uploading when extra protection is needed.
- Set up alerts for unusual sign ins or downloads.
- Keep a written backup and disaster recovery plan.
- Confirm your cloud provider’s current compliance certificates.
- Train staff on safe sharing and password habits.
- Work with a managed partner if your team is small.
- Test your disaster recovery plan at least once a year.
Backup and Disaster Recovery for Cloud GIS
Even in the cloud, GIS cloud backup is still your responsibility. ArcGIS Online protects the platform, but your team should keep backups of important maps, layers, and edits. This helps you recover data if something is deleted or damaged by mistake.
A good ArcGIS disaster recovery plan should cover issues like accidental deletion, account problems, and service outages. Regular backup testing also helps with protecting GIS data in the cloud and finding gaps in cloud GIS security before they become bigger problems.
Security Considerations for Government and Utility GIS
LGovernment agencies and utilities often manage sensitive location data. Cloud security for government GIS includes rules for data storage, audits, and system availability. These are important parts of a strong ArcGIS cloud security plan.
Government teams should check compliance, keep access logs, and follow data retention rules. Utility teams need reliable outage maps and field apps during emergencies. Working with technology solutions for State and Local Government partners can help turn these security requirements into everyday best practices.
| ArcGIS Online strengthens cloud security through its FedRAMP Moderate authorization, meeting more than 300 security controls to protect government geospatial data in the cloud. | ||||||
Common ArcGIS Cloud Security Mistakes
Most ArcGIS cloud security problems are not caused by weak technology. They come from small habits that build up over time. Below are mistakes CyberTech sees most often when reviewing ArcGIS Online security and ArcGIS Enterprise security setups for new clients.
- Leaving default sharing settings turned on for new content.
- Never removing accounts for staff who have left.
- Skipping multi factor authentication because it feels slower.
- Assuming the cloud provider handles all encryption needs.
- Not testing backups until data is already lost.
- Ignoring audit logs until after an incident happens.
How CyberTech Supports ArcGIS Cloud Security
Strong ArcGIS cloud security is not a one time project. It needs ongoing attention as your team, data, and sharing needs change. CyberTech works with GIS and IT teams to close the gaps that often sit between Esri’s platform protections and an organization’s day to day habits.
This includes reviewing ArcGIS identity and access management settings, setting up monitoring and alerts, and building backup and disaster recovery plans that actually get tested. For organizations without a dedicated security team, this kind of support turns a long checklist into a manageable, ongoing routine.
If your team wants a clearer picture of where your current setup stands, a review of your cloud security posture management approach is a practical next step. Combined with steady GIS data security habits like access reviews and backup testing, this keeps your ArcGIS environment protected as it grows.
FAQs
Is ArcGIS Online secure?
Yes. ArcGIS Online includes encryption in transit and at rest, secure data centers, and FedRAMP Moderate authorization for United States government use. However, ArcGIS Online security also depends on your organization’s settings, since user roles, sharing permissions, and account management are configured and maintained by your own team, not by Esri.
What is the shared responsibility model for ArcGIS cloud security?
The ArcGIS shared responsibility model divides duties among Esri, the underlying cloud provider like AWS or Azure, your organization, and any managed services partner. Esri and the cloud provider secure the platform and infrastructure, while your organization manages accounts, sharing settings, and how GIS data is used day to day.
Does Esri encrypt GIS data by default?
Yes. ArcGIS Online encrypts data in transit using TLS 1.2 or later and encrypts stored data using AES 256 bit encryption or stronger. This GIS data encryption happens automatically for hosted content. Extra encryption for customer managed keys or specific compliance needs still requires configuration by your organization or a managed partner.
Who is responsible for user permissions in ArcGIS Online?
Your organization is responsible for user permissions. Esri provides the tools, including roles, groups, and sharing controls, but your admin team decides who gets access, what they can see, and how content is shared. This part of ArcGIS identity and access management is never handled automatically by Esri.
How should an organization back up cloud hosted GIS data?
A solid GIS cloud backup plan includes scheduled exports of maps, layers, and settings, stored separately from your main ArcGIS environment. Organizations should also document clear recovery steps and test them regularly. This approach supports ArcGIS disaster recovery, helping teams restore lost or corrupted data quickly during an outage.
What are the most common ArcGIS cloud security risks?
Common risks include leftover accounts for former employees, maps shared more broadly than intended, weak or reused passwords, and missing multi factor authentication. Most ArcGIS cloud security incidents trace back to these everyday account and sharing mistakes rather than a flaw in Esri’s underlying platform security.
Can State and Local Government agencies store sensitive GIS data in the cloud?
Yes, many agencies do, often using ArcGIS Online’s FedRAMP Moderate authorization as a baseline. Cloud security for government GIS also depends on the agency’s own access controls, audit logging, and records retention practices, so each deployment should be reviewed against specific compliance and public records requirements.
How can an organization identify security gaps in its ArcGIS environment?
Start with a review of user accounts, sharing settings, and login methods across ArcGIS Online and ArcGIS Enterprise. Esri’s Trust Center tools can help, and working with a managed partner adds outside eyes to catch gaps in cloud GIS security that internal teams may overlook.
CyberTech Systems and Software Inc.
Central Arkansas Water's Digital Transformation
"*" indicates required fields