20 unchanged sentences
We track key performance indicators and cybersecurity metrics to evaluate the efficacy of our cybersecurity controls and practices.
−Removed: Further, our cybersecurity program is periodically reviewed by senior members of management and adjusted as needed in an effort to maintain the program’s agility and responsiveness as circumstances and technologies evolve, new cybersecurity threats emerge and regulations change.
−Removed: We separately operate an enterprise risk management (“ERM”) program to identify, evaluate and manage risks.
+Added: Further, our cybersecurity program is periodically reviewed by senior members of management and adjusted as
+Added: needed in an effort to maintain the program’s agility and responsiveness as circumstances and technologies evolve, new cybersecurity threats emerge and regulations change.
+Added: In addition, we operate an enterprise risk management (“ERM”) program to identify, evaluate and manage risks.
Cybersecurity risks are evaluated alongside other critical business risks under the ERM program to align cybersecurity efforts with our broader business goals and objectives.
3 unchanged sentences
We maintain an incident response policy and program focused upon detecting, managing, documenting and reporting incidents affecting our systems and data, including those specific to cybersecurity.
−Removed: In the event of a significant cybersecurity
−Removed: incident, we appoint a dedicated incident team, including a team leader, responsible for managing and coordinating incident response efforts.
+Added: In the event of a significant cybersecurity incident, we appoint a dedicated incident team, including a team leader, responsible for managing and coordinating incident response efforts.
These efforts may include detecting, identifying, defending against, responding to and, if necessary, recovering from cybersecurity incidents.
31 unchanged sentences
This function is led by our Senior Vice President – Information Systems and Technology, who reports to our Chief Financial Officer.
−Removed: The IT Department’s security team, a cross-functional group composed of members with substantial professional and technical information technology experience, oversees the cybersecurity program to help ensure the confidentiality, integrity and availability of the company’s systems and mitigate day-to-day threats and exposures.
+Added: The IT Department’s security team, a cross-functional group composed of members who all have 12 to 26 years of professional and technical information technology experience, oversees the cybersecurity program to help ensure the confidentiality, integrity and availability of the company’s systems and mitigate day-to-day threats and exposures.
It is responsible for measuring and managing cybersecurity risk, including the prevention, detection, mitigation and remediation of cybersecurity incidents and also for implementing cybersecurity policies, programs, procedures and strategies.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.