When passwords are used in the IACS, the asset owner shall have policies and procedures to increase the degree of difficulty to compromise passwords, including complexity, lifetime and reuse.