Creating a “policy and procedure document” is a misnomer, since there is no justifiable reason to have policies and procedures combined into a single document.
Policies and Procedures are distinct but interrelated components of a cybersecurity governance structure. One component to this structure that is often overlooked, or combined into the concept of “policies,” is Standards:
Procedures operationalize both policies and standards and they instruct daily tasks.
In summary, the governance hierarchy flows from Policy (what/why) to Standards (what/how specifics) to Procedures (step-by-step how-to).