Theatre Manager implements fully PCI DSS compliant AES256 encrypted passwords per PCI DSS standard 8.5 and this feature cannot be changed or overridden.
This means all login passwords must be:
|
Changed all passwords from any vendor default password that might be used for installation per PCI DSS 2.1. For example, you must:
|
Never use the Master User account for daily operations. It should only be used when creating other accounts or for other very specialized needs as directed by Arts Management Systems. |
If your network has 'master' domain server (or open directory on OSX) available that could control password authentication for all machines, please ensure that the security policies on the domain/directory server is set to enforce PCI/DSS passwords and that all machines in the network log in using authentication from the server.
If a domain/open directory server is not available to enforce password settings, then each machine/user must use PCI/DSS compliant passwords.
If a user tries more than 6 times to gain access to the system, Theatre Manager automatically resigns the user - which means that they are locked out permanently until manually re-instated per PCI-DSS standard 8.5.13 and 8.5.14 |