Strategic planning requires budget; policy, standard and procedure, development, acquisition, and configuration; security control implementation where continuous monitoring so performance metrics can be achieved.
Governance is where the greatest risks are, as traditional American "Top-Down" models do not address risks within the organizational structure.
Management should better define governance over policy to ensure accuracy and their direction of, and support for, information security and cybersecurity. At the top level, there should be a formal charter and an overall “information security program policy”.
This is why you should get your governance assessed today!