A written statement that communicates management’s intent, objectives, requirements, responsibilities, and standards.
A document that outlines specific requirements or rules that must be met.
Overall intention and direction as formally expressed by management.
Source: COBIT 5
Intentions and direction of an organization as formally expressed by its top management
Source: ISO 27000 - Information Security Standards
For example, an "Acceptable Use" policy would cover the rules and regulations for appropriate use of the computing facilities.