@pseudonym @tek @blit32 So how about you segregate that? Surely it will improve security if you force people to go through a password reset process every odd few weeks when they need access to that kind of data and have forgotten their password, compared to if you let people set a strong password and just be done with it.
Also lots of companies force their employees to change their passwords with alarming frequency even when those employees, or even the company, never handle/s credit card info.