5 unchanged sentences
We define information security and cybersecurity risk as the risk that the confidentiality, integrity or availability of our information and information systems are impacted by unauthorized or unintended access, use, disclosure, disruption, modification or destruction.
−Removed: Information security and cybersecurity risk is an operational risk that is measured and managed as part of our operational risk framework.
−Removed: Operational risk is incorporated into our comprehensive Enterprise Risk Management (ERM) program, which we use to identify, aggregate, monitor, report and manage risks.
−Removed: For more information on our ERM program, see “Risk Management” under “MD&A.”
−Removed: Our Technology Risk and Information Security (TRIS) program, which is our enterprise information security and cybersecurity program incorporated in our ERM program and led by our Chief Information Security Officer (CISO), is designed to (i) ensure the security, confidentiality, integrity and availability of our information and information systems;
+Added: Information security and cybersecurity risk is an operational risk under our enterprise risk taxonomy, which is measured and managed as part of our operational risk management framework.
+Added: Operational risk is incorporated into our risk governance framework, which we use to identify, assess, control, measure & monitor and report & escalate risks.
+Added: For more information on our risk governance framework, see “Risk Management” under “MD&A.”
+Added: Our Technology Risk and Information Security (TRIS) program, which is our enterprise information security and cybersecurity program incorporated in our risk governance framework and led by our Chief Information Security Officer (CISO), is designed to (i) ensure the security, confidentiality, integrity and availability of our information and information systems;
(ii) protect against any anticipated threats or hazards to the security, confidentiality, integrity or availability of such information and information systems;
1 unchanged sentence
The TRIS program is built upon a foundation of advanced security technology, employs a highly trained team of experts and is designed to operate in alignment with global regulatory requirements.
−Removed: The program deploys multiple layers of controls, including embedding security into our technology investments, designed to identify, protect, detect, respond to and recover from information security and cybersecurity incidents.
+Added: The program deploys multiple layers of controls, including embedding security into our technology investments, which are designed to identify, protect, detect, respond to and recover from information security and cybersecurity incidents.
Those controls are measured and monitored by a combination of subject matter experts and a security operations center with integrated cyber detection, response and recovery capabilities.
−Removed: The TRIS program includes our Enterprise Incident Response Program, which manages information security incidents involving compromises of sensitive information, and our Cyber Crisis Response Plan, which provides a documented framework for handling high-severity security incidents and facilitates coordination across multiple parts of the Company to manage response efforts.
+Added: The TRIS program includes our Enterprise Incident Response Program, which manages information security incidents involving compromises of sensitive information, and our Cyber Crisis Response Plan, which provides a documented framework for handling critical security incidents and facilitates coordination across multiple parts of the Company to manage response efforts.
We also routinely perform simulations and drills at both a technical and management level, and our colleagues receive annual cybersecurity awareness training.
−Removed: In addition, we incorporate reviews by our Internal Audit Group and external expertise in our TRIS program, including an independent third-party assessment of our cybersecurity measures and controls and a third-party cyber maturity assessment of our TRIS program against the Cyber Risk Institute Profile standards for the financial sector .
−Removed: We also invest in threat intelligence, collaborate with our peers in areas of threat intelligence, vulnerability management, incident response and drills, and are active participants in industry and government forums.
+Added: The TRIS program aligns with the standards developed by the Cyber Risk Institute Profile for the financial sector and global regulatory requirements and incorporates reviews and assessments by our independent Technical Risk Management Team (part of our second line of defense), our Internal Audit Group (our third line of defense) and external experts.
+Added: In addition, we engage third parties to provide specialized services and capabilities, including vulnerability insights, operation of certain security controls and threat intelligence.
+Added: We also collaborate with our peers in areas of threat intelligence, vulnerability management, incident response and drills, and are active participants in industry and government forums.
Cybersecurity risks related to third parties are managed as part of our Third Party Management Policy , which sets forth the procurement, risk management and contracting framework for managing third-party relationships commensurate with their risk and complexity.
4 unchanged sentences
We continue to assess the risks and changes in the cyber environment, invest in enhancements to our cybersecurity capabilities, and engage in industry and government forums to promote advancements in our cybersecurity capabilities, as well as the broader financial services cybersecurity ecosystem.
−Removed: For more information on risks to us from cybersecurity threats, see “ A major information or cybersecurity incident or an increase in fraudulent activity could lead to reputational damage to our brand and material legal, regulatory and financial exposure, and could reduce the use and acceptance of our products and services .” under “Risk Factors.”
+Added: For more information on risks to us from cybersecurity threats, see “ A major information or cybersecurity incident could lead to reputational damage to our brand and material legal, regulatory and financial exposure, and could reduce the use and acceptance of our products and services .” under “Risk Factors.”
Cybersecurity Governance
4 unchanged sentences
We have multiple internal management committees that are responsible for the oversight of cybersecurity risk.
−Removed: Our Operational Risk Management Committee (ORMC), chaired by our Chief Operational Risk Officer, provides oversight and governance for our information security risk management activities, including those related to cybersecurity.
−Removed: This includes efforts to identify, measure, manage, monitor and report information security risks associated with our information and information systems and potential impacts to the American Express brand.
−Removed: The ORMC escalates risks to our Enterprise Risk Management Committee (ERMC), chaired by our Chief Risk Officer, or our Board based on the escalation criteria provided in our enterprise-wide risk appetite framework.
−Removed: Members of management with cybersecurity oversight responsibilities are informed about cybersecurity risks and incidents through a number of channels, including periodic and annual reports, with the annual report also provided to our Risk Committee, the ORMC and ERMC.
−Removed: Our CISO leads the strategy, engineering and operations of cybersecurity across the Company and is responsible for providing annual updates to our Board, the ERMC and the ORMC on our TRIS program, as well as ad hoc updates on information security and cybersecurity matters.
+Added: Our Technology, Data, Resiliency Risk Committee (TDRRC), co-chaired by our Chief Information Officer and the Head of Technical Risk Management, provides oversight and governance for our information security risk management activities, including those related to cybersecurity.
+Added: This includes efforts to identify, assess, control, measure & monitor and report & escalate information security risks associated with our information and information systems and potential impacts to the American Express brand.
+Added: The TDRRC escalates risks to our Enterprise Risk Management Committee (ERMC), co-chaired by our Chief Executive Officer and our Chief Risk Officer, or our Board based on the escalation criteria provided in our enterprise-wide risk appetite framework.
+Added: Members of management with cybersecurity oversight responsibilities are informed about cybersecurity risks and incidents through a number of channels, including periodic and annual reports, with the annual report on our TRIS program also provided to our Risk Committee, the TDRRC and ERMC.
+Added: Our CISO leads the strategy, engineering and operations of cybersecurity across the Company and is responsible for providing annual updates to our Board, the ERMC and the TDRRC on our TRIS program, as well as ad hoc updates on information security and cybersecurity matters.
Our current CISO has held a series of roles in telecommunications, networking and information security at American Express, including promotion to the CISO role in 2013, and is also responsible for technology risk management.
1 unchanged sentence
Our CISO reports to the Chief Information Officer, information about whom is included in “Information About Our Executive Officers” under “Business.”
−Removed: For more information on our risk governance structure, see “Risk Management — Governance” and “Risk Management —Operational Risk Management Process” under “MD&A.”
+Added: For more information on our risk governance structure, see “Risk Management — Governance and Board Oversight” and “Risk Management —Operational Risk Management Process” under “MD&A.”
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.