Yes, they can be controlled.
You can either buy or write programs to sit on the relevant exit points (see WRKREGINF for a list of exits) that control who can you what, to affect which objects, etc.
Powertech and Netiq both sell products that can control this.
Alternatively, for a more black and white solution, you can use Application Adminstration within Ops Nav (select a server and right-click on it) , to decide who can use/not use the file transfer processes.
You can even centralise Application Administration (and therefore access to the transfer options) by creating an Administration System (Ops Nav, select system, right-click, properties)