Earlier quoted context omitted.
It's a darn good policy if you're the one who is responsible to apply the patches inside of your organisation and you have to test the effect of the patches to the applications running in your company before you actually install them. Applying the patch a few days later typically doesn't noticeably increase your risks but rolling them out unchecked can make some serious damage.
Why can't we just have the choice to apply as soon as it's ready? If you don't want to apply the patches as soon as they're released, then you'd be more than welcome to put them on hold for 4 weeks yourself when it's more convenient.
There are bad guys looking for 0-days out there. If they learn about the vulnerability from the patch, at least the world has the patch before the bad guys do. Now it's the opposite.
Edit: See _wmd's explanation about the technical details of all this in the same level of the answers.