I know that you can password protect a DTS package. I know that you can also edit users authentication layers to disallow them from even seeing DTS packages if they are saved internal to SQL.
Another thing you can do is interrogate who is running the DTS package and based on that determine go/no-go.
BOL has more information on DTS packages and I know that there is a lot here and at support.microsoft.com
Good Luck