PCI Compliance


ETF/A has been enhanced to address PCI Compliance issues by adding an option that allows for LOGONIDs to be SUSPEND(ed) when an attempt is made to signon to the system from an invalid source.   The source must match the source in the user's LIDREC or the LID becomes suspended by ETF/A.   CA-ACF2 Source can be used to control encrypted signon to mitigate credential exposure.

Credentials used to access systems from a non-secure source may become compromised since the LOGONID and PASSWORD are sent in clear text.   ETF/A prevents further usage of such potentially compromised credentials by immediately SUSPEND(ing) the Logonid and EXPIRE(ing) its PASSWORD so it can no longer be used to access the system after an exposure.