This paper discusses the development of a methodology for reasoning about properties of security policies. We view a security policy as a special case of regulation which specifies what actions some agents are permitted, obliged or forbidden to perform and we formalize a policy by a set of deontic formulae. We first address the problem of checking policy consistency and describe a method for solving it. The second point we are interesting in is how to query a policy to know the actual norms which apply to a given situation. In order to provide the user withconsistentanswers, the normativeconflicts which may appear in the policy must be solved. For doing so, we suggest using the notion of roles and define priorities between roles.