Form3 Interview Question

How would you write a security policy document (e.g. cryptographic policy)?