Information Security Policy
The educause.edu site has a chapter from the book Computer and Network Security in Higher Education here.
It does a good job of describing how university security policies should be written.
Here’s an excerpt:
If the goal of institutional policies is to direct individual behavior and guide institutional decisions, then the effectiveness of formal policy statements will depend on their readability and usefulness. Many colleges and universities suffer from the lack of a common and consistent approach or format for writing organizational policies. Policy development is often confused and sometimes derailed because of the misunderstanding and misuse of terms with important meanings to a professional policy administrator, legal counsel, and others.
You can download an archive copy of the chapter here.