I think you are describing the correct behaviour. Pls. note that resulting permissions are always taken as an intersection of both permissions granted by security group and accounts; ie. you need both R permission on sec group and accounts to get an access to items. I'm afraid it cannot be changed.
This question is described in details here: http://docs.oracle.com/cd/E21764_01/doc.1111/e10792/c03_security.htm#BGBGIJDJ