Form3 interview question

How would you write a security policy document (e.g. cryptographic policy)?