Which is more in line with your thinking:
Security policies and procedures should be designed at a point in time and then enforced without modification to prevent arbitrary compromising of any element of the complete security architecture.
----------OR---------
Security policies and procedures need constant review and revision to take into account changes in the systems, staff, and business partners.