Protected systems access rules prohibit credential sharing, require personal control of passwords and OTPs, and mandate prompt breach reporting.
X X X X Extracts X X X X
X X X X Extracts X X X X
....ICEGATE, ECCS and the ACES-GST portal, together with their databases and dependencies, are treated as protected systems, so access is limited to persons authorised in writing. The order requires exclusive personal control of user IDs, passwords and second factors; prohibits writing, storing or transmitting credentials insecurely; bans sharing of passwords and OTPs with anyone, including support staff or vendors; and requires immediate reporting of any request or suspected compromise. Passwords must be changed every ninety days and on disclosure risk, transfer or return from leave, while workstations must not remain logged in unattended. Breach may attract action under the Information Technology Act, BNS, Customs Act and service conduct rules.....
TaxTMI