3 unchanged sentences
We recognize that cybersecurity threats have been increasing in number and severity in the general marketplace and in our industry.
−Removed: In an effort to address these threats, we maintain a cybersecurity risk management strategy that is designed to identify, assess, and manage cybersecurity risks to our business.
+Added: In an effort to address the threat landscape, we maintain a cybersecurity risk management strategy that is designed to identify, assess, manage, and address cybersecurity threats that may have a material impact on our business.
Our cybersecurity risk management strategy includes various policies and components, including cybersecurity assessments, an incident response plan, evaluation of the security practices of our key vendors, and cybersecurity awareness training for our staff.
−Removed: We also leverage third-party technology and security tools and solutions, including alerting and monitoring tools, to support our cybersecurity program.
−Removed: We engage a third-party to conduct a cybersecurity risk assessment on an annual basis, which is informed by the National Institute of Standards and Technology (NIST) Cybersecurity Framework.
+Added: We engage a third-party to conduct a cybersecurity risk assessment on an annual basis, which is informed by the National Institute of Standards and Technology, or NIST Cybersecurity Framework.
We have established a process for our IT security team to track and quantify known IT security risks and our remediation efforts through a cybersecurity risk register.
1 unchanged sentence
The IT security team reports on findings on at least an annual basis to the executive leadership team and the board of directors.
−Removed: We have established a process to review and assess major software vendors’ security practices prior to onboarding, which includes review of the vendors’ responses to cybersecurity questionnaires and security audit reports and certifications, as applicable.
−Removed: Our process also includes contractual requirements for major vendors that process data on our behalf to maintain data protection safeguards.
−Removed: We maintain a security awareness training program for employees, which is provided during onboarding.
+Added: We have established a process to review and assess vendors’ security posture and practices prior to their onboarding.
+Added: Vendors that access, store or process our data are required to respond to a cybersecurity questionnaire and provide applicable security audit reports and certifications.
+Added: Our process also includes contractual requirements to maintain data protection safeguards for vendors that process data on our behalf.
+Added: We maintain a security awareness training program for employees, which is provided through digital microlearning assignments.
We also provide additional mandatory trainings, including phishing training, throughout the year.
+Added: We maintain a Written Information Security Program, or WISP, that defines our organization’s cybersecurity policies and procedures.
+Added: This covers all aspects of cybersecurity, including but not limited to risk management, third party security assessments, security awareness training, acceptable use, endpoint security, patch management, log management, backup and recovery.
We face a number of cybersecurity risks in connection with our business.
2 unchanged sentences
Governance of Cybersecurity Risks
−Removed: Our board of directors is responsible for the general oversight of cybersecurity risks and is informed of key updates to our cybersecurity processes by our audit committee and relevant members of our executive leadership team on at least an annual basis.
−Removed: Our audit committee and members of our executive leadership team meet with our Head of Global Information Technology on a quarterly basis, along with other members of our IT security team from time to time, to discuss cybersecurity matters, such as the emerging cybersecurity threat landscape, significant developments to our cybersecurity processes, and our cybersecurity risk assessments.
+Added: Our board of directors is responsible for the general oversight of cybersecurity risks and is informed of key updates to our cybersecurity processes by relevant members of our executive leadership team on at least an annual basis.
+Added: Our executive leadership team meets with our Head of Global Information Technology, along with other members of our IT security team as needed, to discuss cybersecurity matters, such as the emerging cybersecurity threat landscape, significant developments to our cybersecurity processes, and our cybersecurity risk assessments.
+Added: Senior management is thus kept abreast of the cybersecurity posture and potential risks facing our company.
+Added: Our cybersecurity incident response process is designed to proactively triage, contain, investigate, mitigate and correct all incidents at the direction of the Head of Global Information Technology.
+Added: Critical incidents are assessed for materiality, and escalated to the executive leadership team for awareness, direction and approval as needed.
+Added: Furthermore, significant cybersecurity matters, and strategic risk management decisions are escalated to the Board of Directors, as needed, to provide oversight and guidance on critical cybersecurity issues.
Our IT security team, led by the Head of Global Information Security, Governance and Architecture (“Head of Global ISGA”), is responsible for managing and directing the day-to-day information security strategy of the organization, including oversight of our cybersecurity tools , controls and strategies to protect organization assets, networks and data.
1 unchanged sentence
The Head of Global ISGA routinely reports on cybersecurity risks, projects, and initiatives to the Head of Global Information Technology, who regularly reports to executive management and the audit committee on these matters as described above.
−Removed: The Head of Global ISGA maintains a Certified Information Systems Security Professionals, or CISSP, certification and has approximately two decades of IT security management experience.
−Removed: The IT security team is supported by external
−Removed: vendors that provide managed services for network support, security operations and other IT areas as needed.
+Added: The Head of Global ISGA maintains a Certified Information Systems Security Professionals, or CISSP, certification and has more than two decades of IT security management experience.
+Added: The IT security team is supported by external vendors that provide managed services for network support, security operations and other IT areas as needed.
Our IT security team also meets regularly with our Global Privacy Committee, which oversees our Enterprise Data Protection Program, to coordinate on cybersecurity initiatives and strategy related to protection of personal data.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.