3 unchanged sentences
Farmer Mac recognizes the importance of assessing, identifying, and managing risks associated with cybersecurity threats.
−Removed: These risks include the potential for:
−Removed: • unauthorized access to or acquisition, destruction, alteration, release, theft, or loss of confidential, proprietary, or personal data;
−Removed: • fraud or extortion;
−Removed: • financial and economic loss or costs;
−Removed: • errors in Farmer Mac’s financial statements;
−Removed: • impairment of Farmer Mac’s liquidity;
−Removed: • harm to employees, customers, or vendors;
−Removed: • liability or service interruptions to customers;
−Removed: • loss of customers or vendors;
−Removed: • violation of data protection laws and other litigation and legal risk;
−Removed: • increased regulatory or legislative scrutiny;
−Removed: • reputational damage.
Farmer Mac’s process to identify and assess material risks from cybersecurity threats operates alongside Farmer Mac’s broader overall risk assessment process that contemplates all company risks.
2 unchanged sentences
Farmer Mac’s approach includes:
−Removed: • an enterprise risk management program that includes cybersecurity risk assessment and management and is periodically refreshed;
+Added: • an enterprise risk management program that includes an annual cybersecurity risk assessment and management and is periodically refreshed;
• security reviews designed to identify risks from many new features, software, and vendors, including a security operations center to monitor our systems;
2 unchanged sentences
• a vulnerability management program designed to identify vulnerabilities in the systems and software Farmer Mac uses;
−Removed: • regular cybersecurity testing, including penetration testing on a periodic basis to allow security researchers to help identify vulnerabilities in Farmer Mac’s systems before they mature into real-world cybersecurity threats;
−Removed: • a third-party service provider risk management program designed to identify and mitigate risks associated with third-party vendors and business partners, which includes pre-engagement diligence, contractual security and notification provisions, and ongoing monitoring, as appropriate;
+Added: • regular cybersecurity testing, including third-party penetration testing on a periodic basis to allow security researchers to help identify vulnerabilities in Farmer Mac’s systems before they mature into real-world cybersecurity threats;
+Added: • a third-party service provider risk management program designed to identify and mitigate risks associated with third-party vendors and business partners, which includes pre-engagement diligence, risk assessments, contractual security and notification provisions, and ongoing monitoring, as appropriate;
• a threat intelligence program designed to model and research potential cybersecurity threat actors to identify vulnerabilities and anticipate attack vectors before they are exploited;
−Removed: • cybersecurity controls designed to segment access to systems and to limit access to sensitive data;
+Added: • cybersecurity controls designed to segment access to systems and to limit access to sensitive data, which controls are tested and updated regularly;
• patch management controls aimed at reducing system vulnerabilities;
+Added: • a generative artificial intelligence policy that describes how users may utilize generative artificial intelligence tools in alignment with Farmer Mac's values, ethical standards, and legal requirements, while also safeguarding sensitive information.
These processes vary in maturity across the business, and Farmer Mac works continually to improve them.
Farmer Mac also maintains a privacy and security incident response program to prepare for, detect, respond to, and recover from cybersecurity incidents.
−Removed: That program includes processes to triage, assess severity for, escalate, contain, investigate, and remediate any cybersecurity incident, as well as to comply with any applicable legal obligations and to mitigate brand and reputational damage.
+Added: That program includes processes to triage, assess severity for, escalate, contain, investigate, and remediate any cybersecurity incident, as well as to comply with any applicable legal obligations (including to preserve evidence) and to mitigate brand and reputational damage.
Farmer Mac also conducts regular tabletop exercises to test and fortify the controls of its cybersecurity incident response program.
−Removed: Farmer Mac’s security operations center and incident response team assesses the severity and priority of incidents on a rolling basis, with escalations of cybersecurity incidents provided to Farmer Mac’s management team.
+Added: Farmer Mac’s security operations center and incident response team assesses the severity and priority of incidents on a rolling basis, with escalations of cybersecurity incidents provided to Farmer Mac’s management team and board as appropriate.
If a cybersecurity incident is determined to be a material cybersecurity incident, Farmer Mac’s incident response plan defines the process for any required regulatory disclosures.
5 unchanged sentences
Farmer Mac’s board of directors is actively involved in overseeing the company's cybersecurity risk management.
−Removed: At least once a year, the full board of directors meets with Farmer Mac’s Chief Information Security Officer (“CISO”) to discuss Farmer Mac’s programs and policies related to cybersecurity and risk initiatives and considers them closely both from a risk management perspective and as part of Farmer Mac’s business strategy.
+Added: At least once a year, the full board of directors meets with Farmer Mac’s Chief Information Security Officer (“CISO”) to discuss and approve Farmer Mac’s programs and policies related to cybersecurity and risk initiatives and considers them closely both from a risk management perspective and as part of Farmer Mac’s business strategy.
The board has created a dedicated cybersecurity subcommittee of the enterprise risk committee to oversee Farmer Mac’s cybersecurity programs and practices, including the identification and mitigation of security and privacy risks.
The cybersecurity subcommittee consists of three members of the enterprise risk committee.
−Removed: Two members of that subcommittee have successfully completed the National Association of Corporate Directors (“NACD”) certificate in cyber-risk oversight program.
−Removed: The other member of the subcommittee is the CEO of an energy company and has direct experience managing cyber risk and cybersecurity incidents in that capacity.
−Removed: The chair of the board audit committee has also successfully completed the NACD certificate in cyber-risk oversight program (but is not a member of the cybersecurity subcommittee).
The cybersecurity subcommittee typically meets on a monthly basis with the CISO and other members of Farmer Mac's management team to discuss the performance and effectiveness of Farmer Mac's cyber program and to receive updates on cybersecurity risks, any cybersecurity incidents, and major cybersecurity initiatives.
−Removed: The materials provided to Farmer Mac’s cybersecurity subcommittee and discussed in the meetings include:
−Removed: • updates on Farmer Mac’s data security posture;
−Removed: • results from third-party assessments and testing;
−Removed: • progress towards predetermined risk-mitigation-related goals;
−Removed: • Farmer Mac’s incident response plan;
−Removed: • information about cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to those risks or incidents.
−Removed: At each regular quarterly meeting of the board enterprise risk committee, the cybersecurity subcommittee reviews a summary of the information discussed in the most recent cybersecurity subcommittee meetings.
−Removed: The board of directors has determined that cybersecurity is a priority area of focus and regularly engages with the CISO and other members of senior management in substantial discussions in board and committee meetings to address cybersecurity topics relating to risk management, compliance, strategy, innovation, and governance.
−Removed: Material cybersecurity threat risks are also considered during separate board and committee meeting discussions of important matters like enterprise risk management, operational budgeting, business continuity planning, business transactions and acquisitions, and brand management.
−Removed: Farmer Mac’s CISO manages Farmer Mac’s cybersecurity program, including the identification, evaluation, and prioritization of security risks, as well as the company’s response to security incidents.
+Added: The materials provided to Farmer Mac’s cybersecurity subcommittee and discussed in the meetings may include updates about cybersecurity risks, controls, and assessments, including those from third parties.
+Added: At each regular quarterly meeting of the board enterprise risk
+Added: committee, the cybersecurity subcommittee reviews a summary of the information discussed in the most recent cybersecurity subcommittee meetings.
+Added: Farmer Mac’s CISO manages Farmer Mac’s cybersecurity program, which aligns to industry standards and is reviewed by the cybersecurity subcommittee and approved by the board enterprise risk committee annually, and which includes the identification, evaluation, and prioritization of security risks, as well as the company’s response to security incidents.
The CISO has more than 20 years of experience in cybersecurity and information technology and holds a Master’s degree in Business Administration with a focus on Information Technology.
3 unchanged sentences
The participants in these meetings also discuss their management of, and participation in, the cybersecurity risk management and strategy processes described in this report, including the operation of Farmer Mac’s incident response plan.
−Removed: Farmer Mac provides quarterly cybersecurity training to all employees, board members, and users of Farmer Mac's technology assets.
−Removed: Employees with elevated privileges within the computing environment also receive specialized training tailored to their job responsibilities.
−Removed: Farmer Mac tracks the metrics from the cybersecurity training program and includes the results in dashboard reports shared and discussed with senior management, the board enterprise risk committee, and the board cybersecurity subcommittee.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.