Policy statement must be clearly defined and published. It must also be precise without ambiguity but subject to interpretation by different parties.
If your cybersecurity policies are written unclear, a lot of unnecessary internal overheads of so-called policy exceptions or enforcement issues will be surfaced. Therefore, regular policy review and adjustment is indeed integrated into the policy requirement. And last but not least, don’t be aggressive to write something that is not achievable in the specific business environment.