One goal of the security policy is to emphasize to all stakeholders(employees in particular) that information and data are assets that have a value, and are not just computer files. A security policy will remind employees of the importance and value of information they handle and the risks or exposures that exist. That is, it will help to make a corporate culture that is security conscious. SANS(SysAdmin, Audit, Network, Security) presents a good overview of developing an effective InfoSec policy on their web site.