This article focuses on mandatory access control and security policies within an operating system. It proposes a general methodology for the selection and deployment of policies based on vague descriptions, which are representing operational, functional and security requirements imposed on the operating system. The methodology is extended by generating customized policies and supported by an expert system, as a tool, that offers to minimize, or even completely eliminate, the need for a security consultant as an expert in the problem domain, for designing and selecting policies to harden the operating system and furthermore to design a secure operating system. This methodology moves this key responsibility to either the user or the system administrator.In this article, the methodology is used to generate components of operating system and with conjunction with SELinux reference policy to generate the customized policies, also called custom policies, which will allow setting the security level of certain applications vaguely.