Control 4.4 introduces many new details necessary for it (and you) to receive PCI compliance. From the user perspective, most of these changes are in the area of passwords.
Added the ability to force password changes every 90 days; when a user attempts to login after their password has expired, they will be forced to change their password.
Added the ability to track past passwords so they can't be re-used. To comply with PCI standards, users may not use the previous 4 passwords.
There are new password standards that are being enforced. Password standards are as follows:
Password must be at least seven characters long.
Password must contain at least one number.
Password must contain at least one uppercase character.
Password must contain at least one lowercase character.
If a user has 6 unsuccessful login attempts, they are locked out for 30 minutes. These attempts are logged in the system.
When a user resets a password for another user, they will now be required to confirm their own password.
A second area of change, hidden to most users, is the change in the internal workings of Credit Card security in Control. These include:
Changed all credit card encryption used in Control to be strong encryption as required by PCI.
Created a separate credit card service (C3S) that actually handles all credit card processing and access. Control (via the SSLIP) communicates with C3S for all credit card transactions or to access any credit card information.
For more information on these changes, refer to