Management should never set password policies, but I’ll bet that in a large number of firms that’s the case.