Section 28(2)(iii) in The Credit Information Companies Rules, 2006
(iii)ensure and control, access to the data, information and credit information, terminals, and networks, maintained by them, by means of physical barriers including biometric access control and logical barriers by way of passwords and to ensure that the passwords used in this behalf are not shared by anyone else than who is authorised in this behalf and the passwords are changed frequently on irregular intervals;