You would define your own Membership provider in web.config, and specify any requirements you want in it.
Code:
<membership defaultProvider="myMembershipProvider" userIsOnlineTimeWindow="15">
<providers>
<add name="myMembershipProvider"
connectionStringName="myConnectionString"
applicationName="/"
enablePasswordRetrieval="true"
enablePasswordReset="true"
requiresQuestionAndAnswer="true"
requiresUniqueEmail="true"
passwordFormat="Encrypted"
maxInvalidPasswordAttempts="5"
passwordAttemptWindow="10"
minRequiredPasswordLength="6"
minRequiredNonalphanumericCharacters="0"
type="System.Web.Security.SqlMembershipProvider,
System.Web, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a"/>
</providers>
</membership>