Password policies are set at the Profile level and are not accessible via Permission Sets, and therefore by extension, also not accessible via Permission Set Groups.
Here are examples of Password Policies on a Profile:
User passwords expire in: Never expires
Enforce password history: 3 passwords remembered
Minimum password length: 8 characters
Password complexity requirement: Must include alpha and numeric characters
Password question requirement: Cannot contain password
Maximum invalid login attempts: 10
Lockout effective period: 15 minutes
Obscure secret answer for password resets __
Require a minimum 1 day password lifetime __
Don't immediately expire links in forgot password emails __