Crystal is a reporting tool, it only reads data. It doesn't care about security, because that is a logical contruct, not data.
If you use a stored proc, you can have your logic in there. If you don't use stored procs, then you would need all of the logic in your filter criteria for the report. You will need to include all of the data so that Crystal has enough info to filter out data the user shouldn't see, since Crystal can only ask for data once. I you use an application, the user info will be known and you can pass it along, especially in a stored proc. If you are using Crystal stand alone, you will need to ask the user for their userid...and they can lie. I imagine you could ask for the password as well, but depending on how that is stored/accessed Crystal may not be able to determine if a user is who they say they are.
In short, Crystal doesn't care about security...it is a programmatically decided issue, not data.