Ah, the classic corporate security theater where management proudly announces "industry best practices" while completely ignoring actual NIST standards. Nothing says "we care about security" like forcing users to change perfectly good passwords every 90 days, ensuring they'll write them on sticky notes under their keyboards.
The irony is delicious - the very policies companies implement to "strengthen security" (complex password requirements + frequent changes + no password managers) actually make systems less secure by encouraging bad user behavior.
But hey, at least management can check the "security compliance" box during the next audit, right before the inevitable data breach.