4 unchanged sentences
In an effort to address the threat landscape, we maintain a cybersecurity risk management strategy that is designed to identify, assess, manage, and address cybersecurity threats that may have a material impact on our business.
−Removed: Our cybersecurity risk management strategy includes various policies and components, including cybersecurity assessments, an incident response plan, evaluation of the security practices of our key vendors, and cybersecurity awareness training for our staff.
+Added: We maintain a Written Information Security Program that defines our organization’s cybersecurity policies and procedures.
+Added: This covers all aspects of cybersecurity, including but not limited to:
+Added: • risk management;
+Added: • incident response;
+Added: • third party security assessments and data protection agreements, required of all vendors that access, store or process our data;
+Added: • mandatory security awareness and phishing training through digital microlearning assignments;
+Added: • acceptable use;
+Added: • endpoint security;
+Added: • patch management;
+Added: • log management;
+Added: • backup and recovery.
We engage a third-party to conduct a cybersecurity risk assessment on an annual basis, which is informed by the National Institute of Standards and Technology, or NIST, Cybersecurity Framework.
2 unchanged sentences
The IT security team reports on findings on at least an annual basis to the executive leadership team and the board of directors.
−Removed: We have established a process to review and assess vendors’ security posture and practices prior to their onboarding.
−Removed: Vendors that access, store or process our data are required to respond to a cybersecurity questionnaire and provide applicable security audit reports and certifications.
−Removed: Our process also includes contractual requirements to maintain data protection safeguards for vendors that process data on our behalf.
−Removed: We maintain a security awareness training program for employees, which is provided through digital microlearning assignments.
−Removed: We also provide additional mandatory trainings, including phishing training, throughout the year.
−Removed: We maintain a Written Information Security Program, or WISP, that defines our organization’s cybersecurity policies and procedures.
−Removed: This covers all aspects of cybersecurity, including but not limited to risk management, third party security assessments, security awareness training, acceptable use, endpoint security, patch management, log management, backup and recovery.
We face a number of cybersecurity risks in connection with our business.
3 unchanged sentences
Our board of directors is responsible for the general oversight of cybersecurity risks and is informed of key updates to our cybersecurity processes by relevant members of our executive leadership team on at least an annual basis.
−Removed: Our executive leadership team meets with our Head of Global Information Technology, along with other members of our IT security team as needed, to discuss cybersecurity matters, such as the emerging cybersecurity threat landscape, significant developments to our cybersecurity processes, and our cybersecurity risk assessments.
+Added: Our executive leadership team meets with our Senior Vice President of Information Technology, along with other members of our IT security team as needed, to discuss cybersecurity matters, such as the emerging cybersecurity threat landscape, significant developments to our cybersecurity processes, and our cybersecurity risk assessments.
Senior management is thus kept abreast of the cybersecurity posture and potential risks facing our company.
−Removed: Our cybersecurity incident response process is designed to proactively triage, contain, investigate, mitigate and correct all incidents at the direction of the Head of Global Information Technology.
+Added: Our cybersecurity incident response process is designed to proactively triage, contain, investigate, mitigate and correct all incidents at the direction of the Senior Vice President of Information Technology.
Critical incidents are assessed for materiality, and escalated to the executive leadership team for awareness, direction and approval as needed.
Furthermore, significant cybersecurity matters, and strategic risk management decisions are escalated to the board of directors, as needed, to provide oversight and guidance on critical cybersecurity issues.
−Removed: Our IT security team, led by the Head of Global Information Security, Governance and Architecture (“Head of Global ISGA”), is responsible for managing and directing the day-to-day information security strategy of the organization, including oversight of our cybersecurity tools , controls and strategies to protect organization assets, networks and data.
−Removed: The Head of Global ISGA reports to our Head of Global Information Technology.
−Removed: The Head of Global ISGA routinely reports on cybersecurity risks, projects, and initiatives to the Head of Global Information Technology, who regularly reports to executive management and the audit committee on these matters as described above.
−Removed: The Head of Global ISGA maintains a Certified Information Systems Security Professionals, or CISSP, certification and has more than two decades of IT security management experience.
+Added: Our IT security team, led by the Senior Director of Information Security, Governance and Architecture, or the Senior Director of ISGA, is responsible for managing and directing the day-to-day information security strategy of the organization, including oversight of our cybersecurity tools , controls and strategies to protect organization assets, networks and data.
+Added: The Senior Director of ISGA reports to our Senior Vice President of Information Technology.
+Added: The Senior Director of ISGA routinely reports on cybersecurity risks, projects, and initiatives to the Senior Vice President of Information Technology, who regularly reports to executive management and the audit committee on these matters as described above.
+Added: The Senior Director of ISGA maintains a Certified Information Systems Security Professionals, or CISSP, certification and has more than two decades of IT security management experience.
The IT security team is supported by external vendors that provide managed services for network support, security operations and other IT areas as needed.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.