Seems to me that enforcing frequent PW changing is exactly what you don't want. The reason being that this will push people toward easily remembered (and thus easily broken) PWs -or- to writing down the passwords where they can be stolen. Instead, enforce rules on length, etc and push the users toward better PW management. Expiring PWs to prevent zombie accounts, ...