8 characters minimum, 20 character maximum
must contain at least one non-alpha character (number or special character*)
cannot be the same as the user ID
cannot be repeated for a cycle of 7 password changes
should be difficult to guess *allowable special characters: (numbers 0-9) , ? < > ! @ # $ % ^ & * - _ / | [ ] + = : ; '