{"id":706942,"date":"2024-10-29T19:59:35","date_gmt":"2024-10-30T02:59:35","guid":{"rendered":"https:\/\/www.esri.com\/about\/newsroom\/?post_type=arcnews&#038;p=706942"},"modified":"2024-10-28T14:52:03","modified_gmt":"2024-10-28T21:52:03","slug":"ensuring-robust-security-for-arcgis-online-organizations-across-industries","status":"publish","type":"arcnews","link":"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries","title":{"rendered":"Ensuring Robust Security for ArcGIS Online Organizations Across Industries"},"author":5752,"featured_media":0,"menu_order":0,"template":"","format":"standard","meta":{"_acf_changed":false,"sync_status":"","episode_type":"","audio_file":"","castos_file_data":"","podmotor_file_id":"","cover_image":"","cover_image_id":"","duration":"","filesize":"","filesize_raw":"","date_recorded":"","explicit":"","block":"","itunes_episode_number":"","itunes_title":"","itunes_season_number":"","itunes_episode_type":"","_links_to":"","_links_to_target":""},"categories":[10392,285372,10842],"tags":[201042,283392,25202,19272,283282],"arcnews_issues":[490712],"class_list":["post-706942","arcnews","type-arcnews","status-publish","format-standard","hentry","category-arcgis-online","category-cybersecurity","category-data","tag-data-management","tag-data-security","tag-fedramp","tag-geospatial-data","tag-saas","arcnews_issues-fall-2024","arcnews_sections-news"],"acf":{"short_description":"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.","pdf":{"host_remotely":false,"file":"","file_url":""},"flexible_content":[{"acf_fc_layout":"content","content":"Esri has achieved a significant milestone by securing the Federal Risk and Authorization Management Program (FedRAMP) Moderate authorization for its cornerstone software as a service (SaaS) product, ArcGIS Online.\r\n\r\nIn today\u2019s digital age, as cyber threats continually evolve, organizations across various sectors require dependable solutions to protect their data. FedRAMP Moderate authorization ensures that SaaS providers like Esri meet stringent security standards that are essential for safeguarding sensitive data.\r\n\r\nThis higher compliance level makes a wider range of data eligible for use in ArcGIS Online, which is vital for high-risk sectors, such as finance and health care, that handle sensitive information and are susceptible to data breaches. Additionally, small businesses benefit from these robust security measures, since they gain high-level protection without needing to invest in their own security infrastructure. FedRAMP\u2019s standardized security assessments and ongoing monitoring also improve cybersecurity overall, creating a safer digital environment for everyone.\r\n\r\nThe authorization reflects Esri\u2019s ongoing commitment to software security and compliance. To achieve FedRAMP Moderate authorization, ArcGIS Online security infrastructure and processes underwent rigorous evaluation and received approval from an independent third party. By meeting FedRAMP Moderate standards, ArcGIS Online provides a secure and reliable environment for the storage, processing, and management of moderate-risk data, including financial, health, and personally identifiable information.\r\n\r\nWith growing cybersecurity risks and tightening data privacy regulations, organizations across all sectors can enhance their mapping and spatial analysis workflows by adopting and expanding their use of ArcGIS Online."},{"acf_fc_layout":"content","content":"<h2>Key Benefits for Organizations<\/h2>\r\nThe FedRAMP Moderate authorization for ArcGIS Online presents a range of advantages for organizations that use the SaaS technology, from expanding the types of data that can be stored and processed to strengthening opportunities to collaborate. Read on to find out more.\r\n<h3>A Reliably Secure SaaS Infrastructure<\/h3>\r\nArcGIS Online is the first SaaS-based GIS to achieve FedRAMP Moderate authorization based on the US Department of Commerce\u2019s National Institute of Standards and Technology\u2019s (NIST) SP 800-53 Revision 5 security controls. As a cloud-based solution, ArcGIS Online enhances organizational efficiency by reducing the time and costs required to set up the system, since it eliminates the need to invest in infrastructure, engineering, and system administration. Not only did Esri seamlessly increase the security assurance level of ArcGIS Online, but the company also migrated to NIST\u2019s latest security control revision with no impact to customers.\r\n<h3>Confidently Store and Process Moderate-Impact Data<\/h3>\r\nOrganizations that use ArcGIS Online can confidently collect, maintain, process, disseminate, and dispose of low- or moderate-impact data. This enables users to perform a wide range of geospatial workflows while adhering to the highest standards of security and compliance.\r\n<h3>Enhanced Collaboration and Sharing<\/h3>\r\nOrganizations can expand their collaboration with external stakeholders to include those that need to ensure a higher degree of security compliance. With more data in the system and more people able to work with that data, processes such as sharing data, conducting analysis, and expanding situational awareness become more powerful.\r\n<h3>A Seamless Integration with ArcGIS Enterprise<\/h3>\r\nOrganizations can seamlessly integrate ArcGIS Online with their existing ArcGIS Enterprise deployments to scale beyond the reach of on-premises capacity, facilitating data sharing, collaboration, and comprehensive geospatial workflows.\r\n<h3>Using Advanced Geospatial Capabilities for Critical Operations<\/h3>\r\nFor organizations that engage in emergency response, disaster management, infrastructure planning, and environmental monitoring, they can expand their use of ArcGIS Online to incorporate a wider variety of geospatial data in support of critical operations.\r\n<h3>Value and Relevance for International Users<\/h3>\r\nFor international users that need to align with standards such as the International Organization for Standardization\u2019s ISO\/IEC 27001, the <a href=\"https:\/\/trust.arcgis.com\/en\/\">ArcGIS Trust Center<\/a> provides information on mapping FedRAMP compliance to ISO 27001 security controls. The web page shows how FedRAMP meets international security and compliance requirements, aiding users from around the world in understanding the authorization\u2019s relevance to their needs.\r\n<h3>Depend on Continually Monitored Infrastructure<\/h3>\r\nMaintaining FedRAMP Moderate authorization requires Esri to continuously monitor ArcGIS Online services, perform annual penetration testing, and get approval by an independent third party. Additionally, ArcGIS Online is segmented from corporate systems to ensure system isolation and independence, which foster higher resilience."},{"acf_fc_layout":"content","content":"<h2>The Unique Advantages of Enhanced Security<\/h2>\r\nSince every organization has its own data classifications, IT resources, and specific requirements, each will experience unique benefits from the enhanced security posture of ArcGIS Online.\r\n\r\nFor example, Organization A, which has stringent security requirements and limited IT resources, can use ArcGIS Online FedRAMP Moderate authorization to meet its compliance obligations and integrate ArcGIS Online into its existing systems. This will allow staff members to access and analyze geospatial data without investing in additional hardware or software. Leaders can be confident that the organization\u2019s data is protected at the highest level, building trust with stakeholders and strengthening the organization\u2019s reputation.\r\n\r\nOrganization B, which analyzes utility networks, can now efficiently integrate more workflows into ArcGIS Online while maintaining custom database configurations in its ArcGIS Enterprise deployment. This organization has various options for hybrid deployments with ArcGIS Online and ArcGIS Enterprise, allowing users to incorporate moderate-risk data in workflows that extend beyond the reach of on-premises capacities.\r\n\r\nOrganization C is a federal agency known for its stringent security measures and vast amounts of sensitive data. It offers public information through a scalable external platform. By adopting ArcGIS Online, this agency can now share previously inaccessible data with external stakeholders, improving situational awareness and communication among teams, emergency centers, and local emergency response leaders. This integration streamlines workflows, boosts collaboration, and supports better-informed decision-making.\r\n\r\nIn each of these scenarios, the ArcGIS Online FedRAMP Moderate authorization helps organizations meet their unique security needs. This enables them to leverage the power of GIS technology to collaborate, share data, and develop innovative location-based solutions in new ways, ultimately allowing them to achieve their missions."},{"acf_fc_layout":"content","content":"<h2>Understanding Your Organization\u2019s Responsibility<\/h2>\r\nOrganizations that align their workflows with the FedRAMP Moderate authorization are responsible for implementing and maintaining certain security controls and practices.\r\n\r\nThese organizations should review the Customer Responsibility Matrix (CRM)\u2014available on the Documents tab of the ArcGIS Trust Center once signed in\u2014and determine how best to implement any required changes. The CRM describes elements of user engagement outside Esri\u2019s scope, such as the requirement that end users employ multifactor authentication and categorize datasets to align with Zero Trust Architecture (ZTA) stipulations and privacy regulations, whether at the state or international level.\r\n\r\nVisit the <a href=\"https:\/\/trust.arcgis.com\/en\/\">ArcGIS Trust Center<\/a> to learn more about what the ArcGIS Online FedRAMP Moderate authorization means for your organization."},{"acf_fc_layout":"sidebar","layout":"standard","image_reference":null,"image_reference_figure":"","spotlight_image":null,"section_title":"","spotlight_name":"","position":"Center","content":"Editor\u2019s note: The print edition of this article in the fall 2024 issue of <i>ArcNews<\/i> contains a section called \u201cMore Administrator and User Control\u201d that discusses new AI capabilities in ArcGIS Online. That section is not included in the digital version of the article because these AI capabilities are not currently included in the FedRAMP Moderate authorization. Please see the <a href=\"https:\/\/downloads.esri.com\/resources\/enterprisegis\/ago_fedramp_boundary.pdf\">authorized services document<\/a>\u00a0for more information.","snippet":""}],"references":null},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.9 (Yoast SEO v25.9) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Ensuring Robust Security for ArcGIS Online Organizations Across Industries | Fall 2024 | ArcNews<\/title>\n<meta name=\"description\" content=\"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Ensuring Robust Security for ArcGIS Online Organizations Across Industries | Fall 2024 | ArcNews\" \/>\n<meta property=\"og:description\" content=\"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries\" \/>\n<meta property=\"og:site_name\" content=\"Esri\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/esrigis\/\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.esri.com\/about\/newsroom\/app\/uploads\/2024\/10\/arcnews-banner-ensuringrobust-wide.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Ensuring Robust Security for ArcGIS Online Organizations Across Industries | Fall 2024 | ArcNews\" \/>\n<meta name=\"twitter:description\" content=\"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.esri.com\/about\/newsroom\/app\/uploads\/2024\/10\/arcnews-banner-ensuringrobust-wide.jpg\" \/>\n<meta name=\"twitter:site\" content=\"@Esri\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\/\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries\",\n\t            \"url\": \"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries\",\n\t            \"name\": \"Ensuring Robust Security for ArcGIS Online Organizations Across Industries | Fall 2024 | ArcNews\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\/\/www.esri.com\/about\/newsroom\/#website\"\n\t            },\n\t            \"datePublished\": \"2024-10-30T02:59:35+00:00\",\n\t            \"description\": \"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\/\/www.esri.com\/about\/newsroom\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"ArcNews Articles\",\n\t                    \"item\": \"https:\/\/www.esri.com\/about\/newsroom\/arcnews\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"Ensuring Robust Security for ArcGIS Online Organizations Across Industries\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\/\/www.esri.com\/about\/newsroom\/#website\",\n\t            \"url\": \"https:\/\/www.esri.com\/about\/newsroom\/\",\n\t            \"name\": \"Esri\",\n\t            \"description\": \"Esri Newsroom\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\/\/www.esri.com\/about\/newsroom\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\/\/www.esri.com\/about\/newsroom\/#\/schema\/person\/41c803b2ea8734c36f9c4e9586d1449d\",\n\t            \"name\": \"Amy Ambard\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\/\/www.esri.com\/about\/newsroom\/#\/schema\/person\/image\/\",\n\t                \"url\": \"https:\/\/secure.gravatar.com\/avatar\/f356480172f8ad0bc8d72b855e84171c52f1944c7c7779f3e425d73bf3efa3c7?s=96&d=blank&r=g\",\n\t                \"contentUrl\": \"https:\/\/secure.gravatar.com\/avatar\/f356480172f8ad0bc8d72b855e84171c52f1944c7c7779f3e425d73bf3efa3c7?s=96&d=blank&r=g\",\n\t                \"caption\": \"Amy Ambard\"\n\t            },\n\t            \"url\": \"\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Ensuring Robust Security for ArcGIS Online Organizations Across Industries | Fall 2024 | ArcNews","description":"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries","og_locale":"en_US","og_type":"article","og_title":"Ensuring Robust Security for ArcGIS Online Organizations Across Industries | Fall 2024 | ArcNews","og_description":"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.","og_url":"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries","og_site_name":"Esri","article_publisher":"https:\/\/www.facebook.com\/esrigis\/","og_image":[{"url":"https:\/\/www.esri.com\/about\/newsroom\/app\/uploads\/2024\/10\/arcnews-banner-ensuringrobust-wide.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_title":"Ensuring Robust Security for ArcGIS Online Organizations Across Industries | Fall 2024 | ArcNews","twitter_description":"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.","twitter_image":"https:\/\/www.esri.com\/about\/newsroom\/app\/uploads\/2024\/10\/arcnews-banner-ensuringrobust-wide.jpg","twitter_site":"@Esri","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries","url":"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries","name":"Ensuring Robust Security for ArcGIS Online Organizations Across Industries | Fall 2024 | ArcNews","isPartOf":{"@id":"https:\/\/www.esri.com\/about\/newsroom\/#website"},"datePublished":"2024-10-30T02:59:35+00:00","description":"Esri has secured the FedRAMP Moderate authorization for ArcGIS Online, certifying that the SaaS product meets stringent security standards.","breadcrumb":{"@id":"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.esri.com\/about\/newsroom\/arcnews\/ensuring-robust-security-for-arcgis-online-organizations-across-industries#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.esri.com\/about\/newsroom"},{"@type":"ListItem","position":2,"name":"ArcNews Articles","item":"https:\/\/www.esri.com\/about\/newsroom\/arcnews"},{"@type":"ListItem","position":3,"name":"Ensuring Robust Security for ArcGIS Online Organizations Across Industries"}]},{"@type":"WebSite","@id":"https:\/\/www.esri.com\/about\/newsroom\/#website","url":"https:\/\/www.esri.com\/about\/newsroom\/","name":"Esri","description":"Esri Newsroom","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.esri.com\/about\/newsroom\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.esri.com\/about\/newsroom\/#\/schema\/person\/41c803b2ea8734c36f9c4e9586d1449d","name":"Amy Ambard","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.esri.com\/about\/newsroom\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f356480172f8ad0bc8d72b855e84171c52f1944c7c7779f3e425d73bf3efa3c7?s=96&d=blank&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f356480172f8ad0bc8d72b855e84171c52f1944c7c7779f3e425d73bf3efa3c7?s=96&d=blank&r=g","caption":"Amy Ambard"},"url":""}]}},"sort_order":"4","_links":{"self":[{"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/arcnews\/706942","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/arcnews"}],"about":[{"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/types\/arcnews"}],"author":[{"embeddable":true,"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/users\/5752"}],"version-history":[{"count":0,"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/arcnews\/706942\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/media?parent=706942"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/categories?post=706942"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/tags?post=706942"},{"taxonomy":"arcnews_issues","embeddable":true,"href":"https:\/\/www.esri.com\/about\/newsroom\/wp-json\/wp\/v2\/arcnews_issues?post=706942"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}