<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.blackbaud.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The Spotlight : Security</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Debug Build: 20611.960)</generator><item><title>PA-DSS Aspirations</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/2009/01/23/pa-dss-aspirations.aspx</link><pubDate>Fri, 23 Jan 2009 12:48:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:38955</guid><dc:creator>Nicholai Burton</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/rsscomments.aspx?PostID=38955</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/commentapi.aspx?PostID=38955</wfw:comment><comments>http://forums.blackbaud.com/blogs/patronedge/archive/2009/01/23/pa-dss-aspirations.aspx#comments</comments><description>&lt;p&gt;I&amp;#39;m sure by now you&amp;#39;ve heard plenty about the industry&amp;#39;s movement towards PCI compliance and stamping all programs that touch credit cards with the PA-DSS certification, and not enough about Blackbaud&amp;#39;s progress with Patron Edge. Here is a quick breakdown about some of the features and enhancements we have made in Patron Edge 3.340, and changes that we are continuing to work on as we work to get the PA-DSS stamp put on Patron Edge:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;As of version 3.340, credit card information is now encrypted with an administrator-defined encryption key as transactions are queued to be cleared. 
&lt;li&gt;As soon as a transaction clears, every reference to a credit card number is permanently truncated.&amp;nbsp; The last four digits of the card number are the only data retained. 
&lt;li&gt;Any reports that display transaction data will only show the final four digits of a credit card or less, depending on user security. 
&lt;li&gt;Credit card transaction log files (Tix_PSC logs) no longer store credit card details beyond the last four digits of the card number. 
&lt;li&gt;Password rules, such as password length, rotation, and account lockouts, will go into effect for all user accounts. 
&lt;li&gt;Audit trails will be implemented for all system components in order to be able to recreate system events. 
&lt;li&gt;The installation package will be digitally signed to ensure file integrity and prevent any kind of tampering.&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;The audit of Patron Edge is being performed by a company called &lt;a title="trustwave" href="https://www.trustwave.com/" target="_blank"&gt;Trustwave&lt;/a&gt;, who we are using to audit all of our products in addition to our Hosting environment. Be assured that Patron Edge will be PA-DSS certified, but in the meantime there are more changes in the pipeline that are required to meet this changing standard. Have a question? Leave a note in the comments.&lt;/p&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=38955" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx">Security</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Patron+Edge/default.aspx">Patron Edge</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/PCI+DSS/default.aspx">PCI DSS</category></item><item><title>Manage Your Users' Access to Help Resources</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/2008/10/20/manage-your-users-access-to-help-resources.aspx</link><pubDate>Mon, 20 Oct 2008 14:45:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:37578</guid><dc:creator>Nicholai Burton</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/rsscomments.aspx?PostID=37578</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/commentapi.aspx?PostID=37578</wfw:comment><comments>http://forums.blackbaud.com/blogs/patronedge/archive/2008/10/20/manage-your-users-access-to-help-resources.aspx#comments</comments><description>&lt;p&gt;This post isn&amp;#39;t specifically about Patron Edge, but it is a question that comes up on a weekly basis. The site administrator at your organization has the abiliy to add or remove access to the Blackbaud Support website. It&amp;#39;s both easy and quick to do; here&amp;#39;s the short version:&lt;/p&gt;
&lt;ol style="LIST-STYLE-TYPE:decimal;"&gt;
&lt;li&gt;Click your name at the top right of any Blackbaud web page. 
&lt;li&gt;In the left nav bar under Organization Information, click Invite New User. 
&lt;li&gt;Enter the user&amp;#39;s first name, last name, and email address. 
&lt;li&gt;Mark the new user&amp;#39;s main role and click Submit to send an Invite Email to the user. 
&lt;li&gt;The user receives an invitation email, and you receive a copy for your records. 
&lt;ul style="LIST-STYLE-TYPE:disc;"&gt;
&lt;li&gt;If he doesn&amp;#39;t have a Blackbaud profile, he will click the link to create a new one. 
&lt;li&gt;If he has an existing Blackbaud profile, he can associate it with your organization by clicking &lt;a class="solutionlink" style="TEXT-DECORATION:underline;" href="http://www.blackbaud.com/profile/default.aspx" target="_new"&gt;your name&lt;/a&gt; at the top right of any Blackbaud web page and following these steps: 
&lt;ol style="LIST-STYLE-TYPE:lower-alpha;"&gt;
&lt;li&gt;Confirm Association with the new organization by clicking Submit. 
&lt;li&gt;Enter the confirmation number from the invitation email and click Submit. 
&lt;li&gt;Update any information on your Profile, such as phone number and email address.&lt;/li&gt;&lt;/ol&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;Depending on your turnover, I recommend spending about 10 minutes once a month making sure that your new hires have access to the resources they need to do their job, and that those who are no longer with you don&amp;#39;t have access to things like your support case history.&lt;/p&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=37578" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx">Security</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Administration/default.aspx">Administration</category></item><item><title>Important announcement regarding Patron Edge 3.340</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/2008/09/03/important-announcement-regarding-patron-edge-3-340.aspx</link><pubDate>Wed, 03 Sep 2008 16:50:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:33558</guid><dc:creator>Nicholai Burton</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/rsscomments.aspx?PostID=33558</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/commentapi.aspx?PostID=33558</wfw:comment><comments>http://forums.blackbaud.com/blogs/patronedge/archive/2008/09/03/important-announcement-regarding-patron-edge-3-340.aspx#comments</comments><description>&lt;p&gt;We are making several important changes to the next version of Patron Edge in an effort to meet &lt;a title="PA-DSS rules" href="https://www.pcisecuritystandards.org/security_standards/pa_dss.shtml" target="_blank"&gt;PA-DSS rules&lt;/a&gt;. These changes are required in order for your organization to reach compliance with &lt;a title="PCI standards" href="http://en.wikipedia.org/wiki/PCI_DSS" target="_blank"&gt;Payment Card Industry standards&lt;/a&gt; and continue to process credit cards. The most important changes are these:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Credit card storage&lt;/strong&gt; - Patron Edge 3.340 will no longer store credit card data. In the event that your database is compromised, you can now be assured that no one will be able to manipulate or decrypt the credit card numbers of your patrons.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;SQL upgrades&lt;/strong&gt; - Patron Edge 3.340 will no longer be compatible with MS SQL Server 2000. This is required for our new key management policy, which is the encryption key that your organization will set so that credit cards in transit (waiting to be authorized) cannot be compromised. This change will increase security as only your database administrator will know your encryption key. If someone were to obtain the older, Blackbaud-generated encryption key, your Patron Edge 3.340 database will not be vulnerable. So if your organization is not already running SQL 2005, now is the best time to start planning for an upgrade. &lt;/p&gt;
&lt;p&gt;More details will be coming related to our compliance measures as the next release approaches, both on The Spotlight and on the Patron Edge documentation page.&lt;/p&gt;
&lt;p&gt;Has your organization started planning for PCI compliance? Share your thoughts or best practices in the comments.&lt;/p&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=33558" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx">Security</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Patron+Edge/default.aspx">Patron Edge</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/PCI+DSS/default.aspx">PCI DSS</category></item><item><title>Firefox 3 has been released!</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/2008/06/17/firefox-3-has-been-released.aspx</link><pubDate>Tue, 17 Jun 2008 20:35:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:31492</guid><dc:creator>Nicholai Burton</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/rsscomments.aspx?PostID=31492</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/commentapi.aspx?PostID=31492</wfw:comment><comments>http://forums.blackbaud.com/blogs/patronedge/archive/2008/06/17/firefox-3-has-been-released.aspx#comments</comments><description>&lt;p&gt;&lt;a class="" title="Get Firefox" href="http://getfirefox.com/" target="_blank"&gt;Firefox&lt;/a&gt;, the greatest of the modern browsers, released version 3 of their product just about four hours ago and it has already been downloaded nearly 3 million (million!) times. It&amp;#39;s more secure, prettier, faster and&amp;nbsp;smarter than anything else out there (yes, even you Safari). I encourage all of you to download and use it exclusively for a better browsing experience. If you need to access your Patron Edge Online Administration Site, you can install the excellent &lt;a class="" title="IETab" href="https://addons.mozilla.org/en-US/firefox/addon/1419" target="_blank"&gt;IETab extension&lt;/a&gt; and do it all in one browser. With this extension I don&amp;#39;t think I&amp;#39;ve purposely launched Internet Explorer in two or three years, and haven&amp;#39;t had run-ins with malware of any kind. And now it even integrates with web apps. For example, I can click a mailto link and it will launch my Gmail composer.&lt;/p&gt;
&lt;p&gt;For those who have done a fair amount of PEO design work and had to do any special browser-specific tweaks to make things look the way you want, make sure to test your site in this newest version to ensure that your patrons won&amp;#39;t experience any display issues. The US and Canada together have almost hit the one million download mark, so you can be sure that your patrons are using it already.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.spreadfirefox.com/node&amp;amp;id=0&amp;amp;t=315"&gt;&lt;/a&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=31492" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Web+Design/default.aspx">Web Design</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Performance/default.aspx">Performance</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Usability/default.aspx">Usability</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx">Security</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Patron+Edge+Online/default.aspx">Patron Edge Online</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Stuff+I+Like/default.aspx">Stuff I Like</category></item><item><title>Keep your Administration Site safe</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/2008/06/06/keep-your-administration-site-safe.aspx</link><pubDate>Fri, 06 Jun 2008 15:37:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:31260</guid><dc:creator>Nicholai Burton</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/rsscomments.aspx?PostID=31260</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/commentapi.aspx?PostID=31260</wfw:comment><comments>http://forums.blackbaud.com/blogs/patronedge/archive/2008/06/06/keep-your-administration-site-safe.aspx#comments</comments><description>&lt;div class="snap_preview"&gt;
&lt;p&gt;One of the easiest things you can do to protect your organization online is to ensure the security of your Patron Edge Online Administration site. I bring this up because the majority of Admin sites that I have seen are not well-protected. While an attacker wouldn’t be able to get credit card numbers or anything of that nature via the Administration site, there’s still a lot of potential for mischief, or even damage. An attacker could bring down your site by changing Site Settings, redirect all your menu items to a different site, or all kinds of other bad stuff.&lt;/p&gt;
&lt;p&gt;Luckily, beefing up security is pretty easy. There are three key things to do, and your system administrator will be able to handle all of them in a matter of minutes.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Change your password&lt;/i&gt; - This literally takes seconds but I have seen people who have used PEO for years and still log in with the default login and password. To change the password, go to Administration, System Setup, System Users. Double-click on Supervisor and enter a new password. Done!&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Have different Windows accounts run the public and admin sites&lt;/i&gt; - When using anonymous authentication for your website, the Administration site account should not be the same as the public site account.&amp;nbsp; The default account for anonymous authentication is Internet Guest Account (also called IUSR_MachineName). Keep this one for the public site and use a different one for the Admin site, since it needs greater write and edit privileges on the public site folder. Even better, turn off anonymous access to the Admin site altogether and use Windows Integrated Authentication so that only members of your network are able to get as far as the PEO Admin login page.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Lock down rights to Administration site pieces&lt;/i&gt; - Create logins for each person who needs access (done in the same place where you changed your password above). Then determine what each person should be able to see. Generally a content creator only needs access to the Site Design and Events sections so turn off their ability to get to other administrative pieces.&lt;/p&gt;
&lt;p&gt;What other measures are you taking to secure your website? Leave a message in the comments.&lt;/p&gt;&lt;/div&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=31260" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx">Security</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Patron+Edge+Online/default.aspx">Patron Edge Online</category></item><item><title>Preventing Fraud, Part III (with free stuff!)</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/2008/03/20/preventing-fraud-part-iii-with-free-stuff.aspx</link><pubDate>Thu, 20 Mar 2008 18:16:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:29699</guid><dc:creator>Nicholai Burton</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/rsscomments.aspx?PostID=29699</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/commentapi.aspx?PostID=29699</wfw:comment><comments>http://forums.blackbaud.com/blogs/patronedge/archive/2008/03/20/preventing-fraud-part-iii-with-free-stuff.aspx#comments</comments><description>&lt;div class="snap_preview"&gt;
&lt;p&gt;At the last Blackbaud Conference, one client shared an experience where several cashiers had defrauded her organization via a pretty clever scheme. For cash transactions, the cashier would sell a Member or Child ticket in PE but charge the patron a Full Price admission and then pocket the difference. Once Jeff Heffner and I heard the story, we decided to come up with some reporting ideas to help catch a thief in the act.&lt;img hspace="5" src="http://forums.blackbaud.com/blogs/patronedge/thief.png" align="right" border="0" alt="" /&gt;&lt;/p&gt;
&lt;p&gt;After some brainstorming, we created the Cashier Audit Report. It displays a breakdown of price types sold by each user and their relative percent of total. See &lt;a title="cashier audit" href="http://forums.blackbaud.com/blogs/patronedge/cashier-audit.png" target="_blank"&gt;this screenshot&lt;/a&gt; for an example of the report. With it, you can look for trends and see if anything weird is going on with the distribution of price types. For example, you could see that four of your cashiers sell Student tickets as about 8% of their total sales, but the fifth cashier is selling 15% of his tickets as Student. It could be completely innocent, or it could be that he is letting his friends in at a discount or taking money. Either way, you now have the information you need to take action at your fingertips.&lt;/p&gt;
&lt;p&gt;Alyssa Wigton, our report writer in Professional Services, provided a couple of great tips and helped us get it working in PECRViewer.exe so it can be run directly from Patron Edge. To use it:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Download this set of files: &lt;a href="http://forums.blackbaud.com/blogs/patronedge/Cashier%20Audit.zip"&gt;Cashier Audit.zip&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Add the stored procedure to your PE database&lt;/li&gt;
&lt;li&gt;Add the report into Patron Edge per Knowledgebase solution BB142029&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;As with any custom stuff I give out on the blog, this isn’t an official piece of Patron Edge. My analysts can’t take questions on it, and I can’t be responsible if it leaves the bathroom light on, tramples your flowers, or rearranges the numbers on your speed dial!&lt;/p&gt;
&lt;p&gt;Did you find this report helpful for preventing fraud? Are there any other reports in the system that you use on a regular basis to look out for thieves? Leave a note in the comments. &lt;/p&gt;&lt;/div&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=29699" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Fraud/default.aspx">Fraud</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx">Security</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Theft/default.aspx">Theft</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Free+Stuff/default.aspx">Free Stuff</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Patron+Edge/default.aspx">Patron Edge</category></item><item><title>Preventing Fraud, Part II</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/2008/03/20/preventing-fraud-part-ii.aspx</link><pubDate>Thu, 20 Mar 2008 18:14:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:29698</guid><dc:creator>Nicholai Burton</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/rsscomments.aspx?PostID=29698</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/commentapi.aspx?PostID=29698</wfw:comment><comments>http://forums.blackbaud.com/blogs/patronedge/archive/2008/03/20/preventing-fraud-part-ii.aspx#comments</comments><description>&lt;div class="snap_preview"&gt;
&lt;p&gt;So now that you have locked down the system appropriately per my &lt;a href="http://forums.blackbaud.com/blogs/patronedge/archive/2008/03/19/preventing-fraud-part-i.aspx"&gt;previous post&lt;/a&gt; on the subject, it’s time to take advantage of one of the controls in PE regarding end-of-day procedures. I am referring to the Drawer Cash Out function. If you are not familiar with this feature, it allows your cashiers to enter their end of day cash drawer totals directly into PE, so that you can view their totals side-by-side with the system totals for that drawer. Using this method is easier on the cashier, more secure, and a lot harder to fudge than a paper count-out sheet. Here is how to set up the feature:&lt;br /&gt;&lt;a href="http://forums.blackbaud.com/blogs/patronedge/thief.png"&gt;&lt;img hspace="5" src="http://forums.blackbaud.com/blogs/patronedge/thief.png" align="right" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Enable the feature in Company and for each Cash Drawer:&lt;br /&gt;&lt;/i&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Go to Administration, System Setup, Company and select the Close Drawer tab&lt;/li&gt;
&lt;li&gt;Set Manage Floating Till to Yes and click OK&lt;/li&gt;
&lt;li&gt;Now to to User Setup, Cash Drawers&lt;/li&gt;
&lt;li&gt;Edit each drawer and set Display Actual Payment Done to Yes&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;&lt;i&gt;Set up the payment methods to display on the Cash Out:&lt;/i&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Go to Administration, System Setup, Cash Drawer Payment Methods&lt;/li&gt;
&lt;li&gt;Create a new entry for each kind of bill or coin, where the Value is relative to a dollar. For example, you will make an entry called Quarters with a value of .25&lt;/li&gt;
&lt;li&gt;Create an entry for Check, Clearing and Gift Certificate, if necessary. Feel free to break this down as much as you feel comfortable; some people have one Credit Card entry, some people use one for each card type, and some don’t record this pay type at all on the Cash Out. Just stay consistent with your business practices&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;&lt;i&gt;Disable the Close Drawer function and enable the Drawer Cash Out function in Profiles:&lt;/i&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Go to Administration, User Setup, Profiles&lt;/li&gt;
&lt;li&gt;Edit the needed profiles by expanding the Main Menu section, checking Drawer Cash Out, and unchecking Close Drawer&lt;/li&gt;&lt;/ol&gt;
&lt;p&gt;Not too difficult, right? The reason we turn off the Close Drawer is because only managers should have the ability to do this (or even run draft reports). A cashier should always be reporting her drawer totals blind.&lt;/p&gt;
&lt;p&gt;Are you currently using the Drawer Cash Out function? Do you feel it has helped in preventing fraud or streamlined your end of day process? Leave a note in the comments.&lt;/p&gt;&lt;/div&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=29698" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Fraud/default.aspx">Fraud</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx">Security</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Theft/default.aspx">Theft</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Patron+Edge/default.aspx">Patron Edge</category></item><item><title>Preventing Fraud, Part I</title><link>http://forums.blackbaud.com/blogs/patronedge/archive/2008/03/19/preventing-fraud-part-i.aspx</link><pubDate>Wed, 19 Mar 2008 12:30:00 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:29658</guid><dc:creator>Nicholai Burton</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/rsscomments.aspx?PostID=29658</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://forums.blackbaud.com/blogs/patronedge/commentapi.aspx?PostID=29658</wfw:comment><comments>http://forums.blackbaud.com/blogs/patronedge/archive/2008/03/19/preventing-fraud-part-i.aspx#comments</comments><description>&lt;div class="snap_preview"&gt;
&lt;p&gt;Fraud is a problem in all types of organizations, but it can be especially tough for performing arts organizations and museums since we’re frequently dealing with temps for most of the front desk work. As consultant Leslie Bradford discussed in her Blackbaud Conference session &lt;i&gt;To Catch A Thief&lt;/i&gt;, there are a lot of ways you can get ripped off. Since not everyone was able to make the conference, I’ve decided to do a series of posts on some things you can do to prevent fraud at your organization.&lt;img hspace="5" src="http://forums.blackbaud.com/blogs/patronedge/thief.png" align="right" border="0" alt="" /&gt; &lt;br /&gt;&lt;i&gt;Restrict Access to the system&lt;br /&gt;&lt;/i&gt;Every user should not have a System Administrator profile, and every user should belong to a user group. If a cashier’s only function is selling tickets, he should not have access to Administration or reports &lt;b&gt;at all&lt;/b&gt;. Think carefully about what users need what level of permissions.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Give everyone a unique login and cash drawer&lt;br /&gt;&lt;/i&gt;Your login should be treated as your signature. I know logins like &lt;i&gt;User1&lt;/i&gt;, &lt;i&gt;User2&lt;/i&gt;, &lt;i&gt;User3&lt;/i&gt; are a lot easier to manage than dealing with creating new logins every few months. But it becomes a lot harder to track down where the money went at the end of the day when everyone is using the same generic login.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Use secure passwords&lt;br /&gt;&lt;/i&gt;Require a password that’s different from the login (there is a setting in Administration&amp;gt;Company that can enforce this). Make it have at least eight characters and consist of both letters and numbers. Most importantly, &lt;b&gt;never share your password&lt;/b&gt;. It does no good to give everyone their own login if they can all log in as Supervisor or as each other. Be sure to change passwords at least every 90 days.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;&lt;br /&gt;Change the Supervisor password&lt;br /&gt;&lt;/i&gt;There are two default login/pass combinations that come with PE, depending on how long you’ve had the program. I can’t tell you how many people my analysts get onto screenshare with and see the user enter pe/1 or Supervisor/admin. If your database still uses this default, &lt;b&gt;change it immediately&lt;/b&gt;. Ideally, only one or two people at the organization should have access to this password and if the login is used frequently then the same 90-day password rotation applies here.&lt;/p&gt;
&lt;p&gt;Next time I will discuss using the Drawer Cash Out feature and how it helps in combating fraud at your organization. How are you handling access to the system? Leave a note in the comments. &lt;/p&gt;&lt;/div&gt;&lt;img src="http://forums.blackbaud.com/aggbug.aspx?PostID=29658" width="1" height="1"&gt;</description><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Fraud/default.aspx">Fraud</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Security/default.aspx">Security</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Theft/default.aspx">Theft</category><category domain="http://forums.blackbaud.com/blogs/patronedge/archive/tags/Patron+Edge/default.aspx">Patron Edge</category></item></channel></rss>