The Employees' State Insurance Corporation (ESIC) on December 13, 2022, issued the guidelines on Cyber Security to sensitize government employees, and contractual /outsourced resources and build awareness amongst them on DO'S and DON'TS on cyber-security perspective, these guidelines have been compiled.
The following are the Cyber Security Do's
• Use complex passwords with a minimum length of 10 characters, combining capital letters, small letters, numbers, and special characters.
• Do use hard-to-guess passwords or passphrases.
• Change your passwords at least once in 45 days.
• Always change the password from a virus/malware-free computer.
• Use multi-factor authentication, wherever available.
• Save your data and files on the secondary drive (ex: d:\).
• Maintain an offline backup of your critical data. Regular backups of important data is to be done as per standards.
• Keep your Operating System and BIOS firmware updated with the latest updates/patches.
The following are the Cyber Security Don'ts
• Don't use the same password in multiple services/websites/apps.
• Don't share the password with anyone. The password must not be shared with others, whether you know them or not. Do keep your passwords or passphrases confidential. You are responsible for all activities associated with your credentials.
• Don't save your passwords in the browser or in any unprotected documents.
• Don't write down passwords, IP addresses, network diagrams or other sensitive information on any unsecured material (eg.: sticky/post-it notes, plain paper pinned or posted on your table, etc.)
• Don't save your data and files on the system drive (eg.: c:) or root).
• Don't upload or save any internal/restricted/confidential government data or files on any non-government cloud service (eg.: Google Drive, Dropbox, etc.).
• Don't use obsolete or unsupported Operating Systems.
• Don't connect the official computer/laptop and any other device with a private network (Mobile Hotspot)
The above instructions are to be complied with the help of IT Resources/AMC Agency by the Regional Heads/Institution Heads immediately. They shall be responsible for the proper implementation of these guidelines in the institutions under their control and any cases of cyber-attacks due to non-adherence of these guidelines shall be viewed seriously and suitable action will be taken by the competent authority.
[Notification No. 17012/1/2022-ICT]