Select to view content in your preferred language

Vulnerabilities sharing maps/content to only "My Groups"

554
1
10-24-2018 06:59 AM
SonarBATStructureMAPS
Occasional Contributor

I'm relatively new to ArcGis and creating/sharing web mapping applications. I'm the sole proprietor of my business. I plan to develop maps that can only be accessed/viewed by only my clients which have paid me for my service (this could be 100's of people). Here's a brief overview of the structure of my Organization: 

- Single Use ArcGis Pro license

- Only one member is allowed to be associated to my organization (me - the sole proprietor)

- I have one Group with one member (me)

Last night I uploaded a Shapefile containing sensitive data to my Contents page on ArcGis Online. I shared the Shapefile to only my Group (triple checking it cannot be viewed by the public). I then created a map on ArcGis Online and associated the Shapefile. I made sure the map was only shared to my Group, not the public. Once the map was fully developed, I created a Web Map Application so I could generate a short link and view the map on mobile devices. Again, I was very careful to only share to my Group. I checked all possible options to make sure this map and it's contents are private and can only be seen by my Group/myself (for now while I do some testing). 

This morning when I accessed my ArcGis Online account, I went to the Contents page and saw the Usage for my Shapefile feature set had 530 requests to download. My Web Application had over 50 views. This is very serious and could destroy my business if this information has been copied and distributed. What did I do wrong to expose my sensitive data to the world?!!? There is no way I made these files and map available to the public, unless there's a hidden setting that makes my private file available to the public. 

Please advise. 

Thank you. 

0 Kudos
1 Reply
MikeMinami
Esri Notable Contributor

The first question is do you have an organizational subscription to ArcGIS Online? If you have an organization subscription, it is highly unlikely that your data is shared publicly. Only you control access and if you didn't share it publicly, it shouldn't be. When you create an organizational subscription, you define your organization name, which appears as part of the URL. So, you should have something like https://zzz.maps.arcgis.com where zzz is the name you gave your organization. If your URL is simply https://www.arcgis.com then you have a public account. In these free accounts, all sharing of content is shared publicly. However, it's very clear when sharing items that you're sharing with everyone.

As to why the usage numbers are high, every time you open a map that contains a layer, the view count is incremented. So it may be that your own testing incremented the counts. The same applies to opening a web application that opens a map, that opens layers, all view counts get incremented.

Hope this helps.

Mike

0 Kudos