3 unchanged sentences
Our cybersecurity risk management program is intended to protect the confidentiality, integrity and availability of our critical systems and information.
−Removed: Our program includes processes for identifying, assessing and managing material risks from cybersecurity threats that are guided by the National Institute of Standards & Technology’s Cyber Security Framework, the ISO 27001 international standard for information security and other applicable industry benchmarks.
+Added: At any given time, we face cybersecurity risks and threats, some of which are not fully mitigated, and we routinely address newly discovered vulnerabilities.
+Added: We continuously work to enhance our information security program and risk management efforts.
+Added: Our program includes processes for identifying, assessing and managing material risks from cybersecurity threats that are guided by the National Institute of Standards & Technology’s Cybersecurity Framework, the ISO 27001 international standard for information security and other applicable industry benchmarks.
Our cybersecurity risk management program is integrated into our overall enterprise risk management system and processes, and includes:
−Removed: • a team of professionals within our Global Technology Organization team who are responsible for identifying and mitigating cybersecurity risks and managing our security controls and response activities;
+Added: • a team of professionals within our Global Technology Organization who are responsible for identifying and mitigating cybersecurity risks and managing our security controls and response activities;
• risk assessment processes designed to identify cybersecurity risks to our critical systems, information, products, services and our broader enterprise IT environment;
• an annual tabletop exercise to simulate a response to a cybersecurity incident;
−Removed: • mandatory training annually and upon hiring for all employees on data privacy and cybersecurity topics.
−Removed: When appropriate, we utilize independent, external service providers to assess, test or otherwise assist with certain aspects of our cybersecurity risk management program and related processes, including for penetration testing, threat monitoring and incident response.
+Added: • mandatory training annually and upon hiring for all employees and contractors on data privacy and cybersecurity topics.
+Added: When appropriate, we utilize independent, external service providers to assess, test or otherwise assist with certain aspects of our cybersecurity risk management program and related processes, including for penetration testing, threat
+Added: monitoring and incident response.
We also employ a vendor risk assessment process to mitigate risks presented by certain third-party service providers, and we require such providers to manage their cybersecurity risks in conformance to industry standards, notify us of relevant cybersecurity events and satisfy additional contractual requirements.
As of the date of this Annual Report on Form 10-K, we are not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition .
−Removed: Risk Factors, “Cyber security threats or other security breaches, or any other impairment of the confidentiality, integrity or availability of our IT systems, or those of one or more of our corporate infrastructure vendors, could have a material adverse effect on our business” in this Annual Report on Form 10-K for additional information about our cybersecurity-related risks.
+Added: However, despite our efforts, we cannot eliminate all risks from cybersecurity threats, or provide assurances that we have not experienced undetected cybersecurity incidents.
+Added: For additional information about our cybersecurity-related risks, see Item 1A.
+Added: Risk Factors in this Annual Report on Form 10-K.
Cybersecurity Governance
Our Board of Directors is actively involved in overseeing our cybersecurity risk management and shares oversight responsibility and processes with the Audit Committee of the Board of Directors (the “Audit Committee”).
−Removed: Our management, including our Chief Information Officer (“CIO”), in consultation with our Chief Information Security Officer (“CISO”), reviews with the Audit Committee at least quarterly our cybersecurity security policies, practices and protective measures, threat intelligence, cybersecurity incidents and related risks.
+Added: Our management, including our Chief Information Officer (“CIO”), in consultation with our Chief Information Security Officer (“CISO”), reviews with the Audit Committee quarterly, or more frequently as determined to be necessary or advisable, regarding our cybersecurity security policies, practices and protective measures, threat intelligence, cybersecurity incidents and related risks.
At least quarterly, our CIO also provides the Audit Committee with an update on our enterprise security program that includes procedures and policies for testing vulnerabilities, responding to cybersecurity threats, and training and evaluating our employees.
The Audit Committee and management also update our Board of Directors at least quarterly on our cybersecurity performance and risk profile and the effectiveness of our cybersecurity processes.
+Added: We also have protocols in place for escalating certain cybersecurity incidents to the Audit Committee and the Board of Directors.
Our management, including our CIO and CISO, are responsible for assessing and managing material risks from cybersecurity threats.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.