This online help file is for EFT Server version 6.2.x. For other versions of EFT Server, please refer to http://help.globalscape.com/help/index.html. (If the Index and Contents are hidden, click Show Contents pane in the top left corner of this topic.) |
From the PCI DSS:
To ensure critical data can only be accessed by authorized personnel, systems and processes must be in place to limit access based on need to know and according to job responsibilities.
PCI DSS Requirement |
How Requirement is Addressed with EFT Server |
7.1 Limit access to computing resources and cardholder information only to those individuals whose job requires such access. |
Each user account defined in EFT Server inherits settings from the Settings Template, or you can define settings specific to a user. Permission Groups set user virtual file system (VFS) permissions to folders. You can enable and disable user access to EFT Server resources by user, Group, Settings Template, Site, and Server. You can also grant or deny access by IP address. |
7.2 Establish a mechanism for systems with multiple users that restricts access based on a user’s need to know. |
EFT Server provides groups, virtual folders, and settings templates for segregating and controlling user access. In addition, delegated administrators or help-desk users can be granted varying levels of control over server settings and resources. |