Security policy
The written statement of what your organization requires regarding security, and who is responsible for what.
Policy sets the rules; procedures describe how they are carried out; standards specify the technical detail. Frameworks expect all three, and expect them to be approved, communicated, and reviewed.
The failure mode is a downloaded template describing an organization that does not exist. A policy contradicted by daily practice is an audit finding rather than a control.
Where this comes up
Security policy sits inside our compliance and frameworks work. If you are trying to work out what this means for your own environment rather than in the abstract, that is the page worth reading next, and a short call will get you a straight answer faster than either.