Security Discipline and Credential Management Guidelines for Access to Protected Systems (ICEGATE, ECCS and ACES-GST Portal)
Show AI Summary
Credential sharing prohibition governs access to protected systems, with strict password discipline and mandatory compromise reporting.
Sharing of user IDs, passwords, one-time passwords and other authentication factors for access to CBIC protected systems is strictly prohibited. The authorised user must keep credentials under exclusive personal control, must not record, store, transmit or leave them accessible to others, and must not share them with colleagues, vendors, contractual support personnel or helpdesk resources. On suspected or actual compromise, the user must disable the user identifier, report the incident, and preserve the device and records for investigation. Sharing credentials or using another person's credentials may attract penal action under the relevant laws and service rules.