Security policy

What is a security policy and why does an organization need a security policy?
What are criticisms of security policies?
What could be implemented to improve on the criticisms?