4 unchanged sentences
The Company’s cybersecurity policies, standards, processes, and practices are based on recognized frameworks established by the National Institute of Standards and Technology, the International Organization for Standardization and other applicable industry standards and are standalone from the Company’s overall risk management system and processes.
−Removed: In general, the Company seeks to address material cybersecurity threats through a company-wide approach that addresses the confidentiality, integrity, and availability of the Company’s information systems or the information that the Company collects and stores, by assessing, identifying and managing cybersecurity issues as they occur.
+Added: In general, the Company seeks to address
+Added: material cybersecurity threats through a company-wide approach that addresses the confidentiality, integrity, and availability of the Company’s information systems or the information that the Company collects and stores, by assessing, identifying and managing cybersecurity issues as they occur.
Cybersecurity Risk Management and Strategy
29 unchanged sentences
On an annual basis, the Board will discuss the Company’s approach to overseeing cybersecurity threats with the Company’s Chief Information Security Officer (“CISO”) and other members of senior management.
−Removed: The CISO, in coordination with senior management, works collaboratively across the Company to implement a program designed to defend the Company’s information systems from cybersecurity threats and to promptly respond to any material cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
+Added: The CISO, in coordination with senior management, works collaboratively across the Company to implement a program designed to defend the Company’s information systems from cybersecurity threats and to promptly respond to any material
+Added: cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
To facilitate the success of the Company’s cybersecurity program, cross-functional teams throughout the Company address cybersecurity threats and respond to cybersecurity incidents.
1 unchanged sentence
To ensure prompt reporting and compliance with SEC requirements, the Board has adopted a “Cybersecurity Incident Materiality Assessment Policy.”
−Removed: The CISO has served in various roles in information technology and information security for over 20 years, including serving as the Chief Information Security Officer of PAE Incorporated prior to its acquisition by Amentum.
−Removed: The CISO holds an undergraduate degree in computer science from the University of Maryland and a graduate degree in information security and assurance from Carnegie Mellon University.
−Removed: The CISO has attained the professional certifications of Certified Information Systems Security Professional (“CISSP”) and Certified Information Systems Manager.
+Added: The CISO is a retired Air Force veteran who has served in various roles in information technology, information security and the U.S.
+Added: Government for over 30 years.
+Added: The CISO most recently served as the Chief Information Security Officer of Optiv Security and previously served as the Executive Director, Classified Cybersecurity, at Lockheed Martin.
+Added: The CISO holds an associates degree in criminal justice from the Community College of the Air Force, an undergraduate degree in information technology from the University of Phoenix, and a graduate degree in information systems security from Colorado Technical University.
+Added: The CISO has attained the professional certifications of Certified Information Systems Security Professional with a concentration in Management, Certified Chief Information Security Officer, and Certified Ethical Hacker.
Material Effects of Cybersecurity Incidents
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.