Where password-based authentication is used the IACS shall enforce configurable password strength including minimum length, complexity, history and lifetime appropriate to SL-T.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.