UNRESOLVED STAFF COMMENTS
−Removed: 1C, Cybersecurity
Cybersecurity
+Added: Cybersecurity
Management and Strategy
10 unchanged sentences
We have developed a cybersecurity program
−Removed: following the National Institute of Standards and Technology (“NIST”) cybersecurity framework that include mechanisms, controls,
−Removed: technologies, and systems designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting
−Removed: the data and maintain a stable information technology environment.
−Removed: For example, we conduct penetration and vulnerability testing, and
−Removed: data recovery testing on a periodic basis.
−Removed: In addition, we consult with outside advisors and experts, when appropriate, to assist with
−Removed: assessing, identifying, and managing cybersecurity risks, including to anticipate future threats and trends, and their impact on the
−Removed: Company’s risk environment.
+Added: following the National Institute of Standards and Technology cybersecurity framework that includes mechanisms, controls, technologies,
+Added: and systems designed to prevent or mitigate data loss, theft, misuse, or other security incidents or vulnerabilities affecting the data
+Added: and maintain a stable information technology environment.
+Added: For example, we conduct penetration and vulnerability testing, and data recovery
+Added: testing on a periodic basis.
+Added: In addition, we consult with outside advisors and experts, when appropriate, to assist with assessing, identifying,
+Added: and managing cybersecurity risks, including to anticipate future threats and trends, and their impact on the Company’s risk environment.
Risk Management
15 unchanged sentences
as experience in implementing security frameworks such as International Organization for Standardization (“ISO”) 27001 and
−Removed: Our Information Technology Security and Risk Manager has a PhD in a scientific field and various information security certifications
−Removed: such as Certified Ethical Hacker (“CEH”) and Holistic Information Security Practitioner (“HISP”).
−Removed: decades of experience in managing information technology environments and information security such as security architecture, security
−Removed: operations and governance risk and compliance.
+Added: the National Institute of Standards and Technology.
+Added: Our Information Technology Security and Risk Manager has a PhD in a scientific field
+Added: and various information security certifications such as Certified Ethical Hacker and Holistic Information Security Practitioner.
+Added: also has decades of experience in managing information technology environments and information security such as security architecture,
+Added: security operations and governance risk and compliance.
report on our information security program, including the results of periodic testing, to the Audit Committee of the Board of Directors
16 unchanged sentences
Additional information on cybersecurity risks we face is discussed in Part I, Item 1A, “Risk
−Removed: Factors,” under the heading “Risks related to cybersecurity.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.