Randy T. answered 12/30/20
Its easy if you learn the fundamentals!
Password management policy - password complexity, how often it is reset, length, etc
Data retention / deletion policy - how long is data stored, is stored data encrypted, how is data purged
Incident response policy - virus infection, info breach, account takeover, how and who responds do these?
Information sharing policy - how is information shared, who can you share with? (no forwarding outside domain)
Endpoint security policy - endpoint HDDs are encrypted, secure-boot, MDM managed, remote wipe if lost or stolen, etc.