This document provides an overview of WS-Security Policy, which defines a framework for expressing security requirements for web services using policies. It discusses how WS-Security Policy builds on WS-Policy to allow endpoints to express security requirements through policy assertions. These include protection assertions to specify signed or encrypted parts, token assertions to specify required token types, and binding assertions to define how messages are secured. The document also covers how policies can be associated with WSDL definitions and how policy compatibility and intersections are defined.