A plan or course of action intended to guide decisions and actions.
Every large organization should have a large and well-defined set of policies for their organization. Policies are a form of security control and define, at a high-level, how many of the procedures and business processes within the company are to be performed. Without policies, there would be chaos within organizations and it would be impossible to maintain secure procedures throughout the organization.
The SANS organization provides a good set of policy templates that can be implemented in just about any organization. Check them out here!