11 unchanged sentences
Further, we maintain a vendor security review program, which is designed to provide an assessment of the security practices of those third-party vendors that process Adobe non-public data or connect to our networks.
−Removed: We maintain an information security incident response plan designed to monitor, analyze, address, escalate and report cybersecurity incidents, and escalate certain cybersecurity incidents to members of management depending on the circumstances, including our Chief Security Officer (“CSO”), Chief Cybersecurity Legal and Privacy Officer (“CCPO”), Chief Financial Officer, Chief People Officer, President of Digital Media, President of Digital Experience, General Counsel and Chief Executive Officer.
+Added: We maintain an information security incident response plan designed to monitor, analyze, address, escalate and report cybersecurity incidents, and escalate certain cybersecurity incidents to members of management depending on the circumstances.
For a description of the risks from cybersecurity threats that may materially affect us, see the risks described in the section titled “Risk Factors” contained in Part I, Item IA of this report, including under the headings “Security incidents, improper access to or disclosure of our customers’ data or other cybersecurity incidents may harm our reputation and materially and adversely affect our business.”
−Removed: Our Board of Directors (the “Board”) addresses cybersecurity risk management as part of its general oversight function.
−Removed: The Audit Committee of the Board (the “Audit Committee”) has oversight of enterprise risks, including risks related to cybersecurity.
−Removed: In this regard, the Audit Committee reviews and discusses with management the adequacy and effectiveness of our information security, technology and privacy policies and the internal controls regarding these areas.
−Removed: Our Audit Committee receives regular cybersecurity updates about general cybersecurity risks from our CSO and updates about the prevention, detection, mitigation and remediation of cybersecurity incidents from our CSO and CCPO.
−Removed: Cybersecurity updates presented to the Audit Committee are reported to the Board by the Audit Committee Chair .
−Removed: We also have a Cyber Disclosure Committee, comprised of cross-functional leaders including finance, risk, operations and investor relations and led by the CSO and CCPO, that meets to assess certain incidents and makes determinations regarding materiality.
−Removed: Additionally, our CSO and CCPO identify certain cybersecurity risks that are reviewed as part of the enterprise risk management framework and presented to the Board and the Audit Committee on an annual basis.
−Removed: Our cybersecurity risk assessment and management processes are implemented and maintained by certain management members, including our CSO and CCPO , whom each has extensive cybersecurity experience in their respective areas of responsibility and expertise.
−Removed: Our CSO, who reports to the Chief Financial Officer, has primary responsibility for hiring appropriate information security personnel and managing workloads of information security personnel, engaging and overseeing third-party cybersecurity consultants, approving budgets and cybersecurity processes, preparing for incident response, reviewing security assessments and other security-related reports, communicating key priorities to relevant personnel, including the security incident response team, assessing and managing Adobe’s overall cybersecurity strategy, standards, risk management (in consultation with the cybersecurity risk steering committee) and processes.
−Removed: Our CCPO, who reports to the General Counsel, has primary responsibility for the legal aspects of the cybersecurity program, including assessing and providing advice on our cybersecurity strategy, standards, risk management, policies, processes and legal obligations.
−Removed: Our CSO and CCPO are supported by a cybersecurity team comprised of cybersecurity, information security, information technology, operations and legal executives and professionals.
+Added: Our Board of Directors (the “Board”) addresses cybersecurity risks as part of its general oversight function.
+Added: Our Audit Committee of the Board (the “Audit Committee”) oversees enterprise risks, including cybersecurity risks, and the adequacy and effectiveness of our information security, technology and policies and our internal controls regarding these areas.
+Added: The Audit Committee receives regular cybersecurity updates from our Chief Security Officer (“CSO”), in conjunction with senior cyber legal and other professionals, and reports those updates to the Board.
+Added: The updates address topics such as cybersecurity risks and the prevention, detection, mitigation and remediation of cybersecurity incidents.
+Added: We have a Cyber Disclosure Committee, comprised of our CSO, cyber legal professionals and other cross-functional leaders, that meets regularly to assess and make determinations regarding certain cybersecurity incidents, and have an escalation process to inform management and the Audit Committee when appropriate.
+Added: Additionally, our CSO identifies certain cybersecurity risks that are reviewed as part of the enterprise risk management framework and periodically presented to the Board and the Audit Committee.
+Added: Our cybersecurity risk assessment and management processes are implemented and maintained by management, including our CSO and our cyber legal professionals , whom each has extensive cybersecurity experience in their respective areas of responsibility and expertise.
+Added: Our CSO, who reports to the Chief Financial Officer, has primary responsibility for the strategy, engineering and operations of cybersecurity across Adobe in partnership with our executive-level product leaders and our cyber legal professionals, who report to the Chief Legal Officer, and have primary responsibility for the legal aspects of cybersecurity across Adobe.
+Added: Our CSO is supported by a team of cybersecurity, information security, information technology, operations and legal executives and professionals.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.