Chapter 5 Compliance : Configuring FortiGate units for PCI DSS compliance : Controlling access to the CDE network : Administrator access security
  
Administrator access security
To accommodate the requirement for unique identification of each user, the generic admin account should either be assigned to only one administrator or not used at all. You can create an administrator account for each administrator in System > Admin > Administrators.
If an administrator always works from the same workstation, consider using the Trusted Host feature. The administrator will be able to log in only from a trusted IP address. You can define up to three trusted IP addresses per administrator.
Administrative access must also be enabled per network interface. Go to System > Network > Interface to edit the interface settings. Enable administrative access only on interfaces where you would expect the administrator to connect. Allow only secure connection protocols, HTTPS for web-based access, SSH for CLI access.