UNRESOLVED STAFF COMMENTS
−Removed: CYBERSECURITY
+Added: CYBERSECURIT Y
Risk Management and Strategy
−Removed: We have established policies and processes for assessing, identifying, and managing material risks from cybersecurity threats, and have integrated these processes into our overall risk management systems and practices.
−Removed: We routinely assess material risks from cybersecurity threats, including any potential unauthorized attack on, or use of, our information systems that may result in adverse effects on the confidentiality, integrity, or availability of our information systems or any information stored therein.
−Removed: Our data breach management policy classifies potential incidents by risk levels, and we typically prioritize our incident mitigation and impact evaluation efforts based on those risk classifications, while focusing on maintaining the resiliency of our systems.
−Removed: These risk assessments include identifying reasonably foreseeable potential internal and external risks, the likelihood of occurrence and any potential damage that could result from such risks, and the sufficiency of existing policies, procedures, systems, controls, and other safeguards in place to manage such risks.
+Added: We have established policies and processes for assessing, identifying, and managing material risks from cybersecurity threats,
+Added: and have integrated these processes into our overall risk management systems and practices.
+Added: We routinely assess material risks
+Added: from cybersecurity threats, including any potential unauthorized attack on, or use of, our information systems that may result in
+Added: adverse effects on the confidentiality, integrity, or availability of our information systems or any information stored therein.
+Added: Our security incident response framework classifies potential incidents by risk levels, and we prioritize our incident mitigation
+Added: and impact evaluation efforts based on those risk classifications or security incident categories, while focusing on maintaining
+Added: the resiliency of our systems.
+Added: The risk assessments support the identification of reasonably foreseeable internal and external
+Added: risks, the likelihood of occurrence and any potential damage that could result from such risks, and the sufficiency of existing
+Added: policies, procedures, systems, controls, and other safeguards in place to manage such risks.
Following these risk assessments, we design, implement, and maintain reasonable safeguards to minimize the identified risks;
1 unchanged sentence
update existing safeguards as necessary;
−Removed: and monitor the effectiveness of our safeguards.
−Removed: Some of the other steps we have taken to detect, identify, assess, classify, and attempt to mitigate cyber security and risks include:
+Added: and monitor the
+Added: effectiveness of our controls.
+Added: Some of the other steps we have taken to detect, identify, assess, classify, and attempt to mitigate
+Added: cybersecurity risks include:
• Adopting and periodically reviewing and updating information security and privacy policies;
1 unchanged sentence
• Complying with the Payment Card Industry Data Security Standard (PCI-DSS);
−Removed: • Implementing an Information Security Management System (ISMS) that is certified as meeting the requirements of the ISO 27001 standard;
−Removed: • Implementing a Privacy Information Management System (PIMS) that complies with the requirements of the ISO 27701 standard;
−Removed: • Engaging an industry-leading, suitably qualified and experienced third party to independently evaluate our information security systems on a regular basis;
−Removed: • Adopting a vendor risk management program, which includes receiving the results of cybersecurity evaluations conducted on certain vendors engaged in high-risk data processing;
−Removed: • Providing security and data protection training and awareness to our employees, contractors and key partners with access to sensitive information and systems;
+Added: • Implementing an Information Security Management System (ISMS) that is designed to generally align with the
+Added: requirements of the ISO 27001 standard;
+Added: • Implementing a Privacy Information Management System (PIMS) that is designed to align with the requirements of
+Added: the ISO 27701 standard;
+Added: • Engaging an experienced third party to independently evaluate our information security systems on a regular basis;
+Added: • Adopting a vendor risk management program, which includes receiving the results of cybersecurity evaluations
+Added: conducted on certain vendors engaged in high-risk data processing;
+Added: • Providing security and data protection training and awareness to our employees, contractors and key partners with
+Added: access to sensitive information and systems;
• Maintaining cyber liability insurance.
−Removed: At this time, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
−Removed: For additional information regarding risks from cybersecurity threats, please refer to Item 1A “Risk Factors -Cybersecurity and Technology Risks.
−Removed: Cybersecurity and data protection falls under our overall risk management and oversight.
−Removed: Our Board of Directors periodically receives reports from our operations committee, cybersecurity management, external professional advisors, and other relevant Company personnel regarding various types of risks faced by the Company and the Company’s risk mitigation efforts related thereto, including cybersecurity risks and related mitigation efforts.
−Removed: The Board also receives presentations from management regarding trends in cybersecurity risks and risk mitigation initiatives and plans, including briefings on recent breaches at other companies and key takeaways and lessons learned that are applicable to our business.
−Removed: The Board will also periodically review key cybersecurity-related benchmarks for the Company.
−Removed: The Company has a dedicated Security Forum and a Data Protection Committee comprising members from our senior leadership that convene on a regular basis to receive updates from our operations committee, cybersecurity management, external professional advisors, and other relevant Company personnel about the Cybersecurity & Privacy programs we have in place;
−Removed: discuss and assess material risks and planned risk mitigation, incidents and planned remediation efforts, trends observed, consider cybersecurity-related proposals, and review and adopt changes in cybersecurity policies.
+Added: Although certain of our systems are designed to align with requirements of ISO 27701, this does not mean that we will meet
+Added: any particular technical standards, specifications, or requirements, but rather we use ISO 27701 and other cybersecurity
+Added: standards as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
+Added: At this time, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity
+Added: incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business
+Added: strategy, results of operations, or financial condition.
+Added: For additional information regarding risks from cybersecurity threats,
+Added: please refer to Item 1A “Risk Factors -Cybersecurity, Data Privacy and Technology Risks.
+Added: Cybersecurity and data protection are integrated into our overall risk management and oversight framework.
+Added: Directors periodically receives reports from our committees, cybersecurity management, external professional advisors, and
+Added: other relevant Company personnel regarding various types of risks faced by the Company and the Company’s risk mitigation
+Added: efforts related thereto, including cybersecurity risks and related mitigation efforts.
+Added: The Board also receives presentations from management regarding trends in cybersecurity risks and risk mitigation initiatives
+Added: and plans, including briefings on recent breaches at other companies and key takeaways and lessons learned that are applicable
+Added: to our business.
+Added: The Board will also periodically review key cybersecurity and data privacy related benchmarks for the
Management’s Responsibilities
−Removed: In the event we identify a potential cybersecurity issue, we have defined procedures for responding to such issues, including procedures that address when and how to engage with Company management, our Board of Directors, other stakeholders, and law enforcement when responding to such issues.
−Removed: We have a dedicated management team overseeing our cybersecurity initiatives, led by our Chief Information Officer, our Vice President and Global Data Privacy Officer, and our Vice President of Cybersecurity.
−Removed: Our Chief Information Officer has over 25 years’ experience overseeing and managing information technology teams and complex IT systems, and our Vice President of Cybersecurity has over 15 years’ experience developing and managing cybersecurity functions and strategies.
−Removed: Our Vice President of Global Data Privacy is a recognized leader in the industry with over 7 years of experience in managing global data privacy programs.
−Removed: Our cybersecurity management team regularly meets with senior executives and other team members to provide oversight with respect to our cybersecurity risk detection, identification, assessment, classification, and mitigation efforts.
+Added: In the event we identify a potential cybersecurity issue, we have defined procedures for responding to such issues, including
+Added: procedures that address when and how to engage with Company management, our Board of Directors, other stakeholders, and
+Added: law enforcement when responding to such issues.
+Added: We have a dedicated management team overseeing our cybersecurity initiatives, led by our Chief Information Officer , our Vice
+Added: President and Global Data Privacy Officer, and our Vice President of Cybersecurity.
+Added: Our Chief Information Officer has over 25
+Added: years’ experience overseeing and managing information technology teams and complex IT systems, and our Vice President of
+Added: Cybersecurity has over 15 years’ experience developing and managing cybersecurity functions and strategies.
+Added: President of Global Data Privacy is a recognized leader in the industry with over 7 years’ experience in managing global data
+Added: privacy programs.
+Added: Our cybersecurity management team regularly meets with industry trust groups, senior executives and other team members to
+Added: provide oversight with respect to our cybersecurity risk detection, identification, assessment, classification, and mitigation
+Added: The Company has a dedicated Security Forum and a Data Protection Committee comprising members from our senior
+Added: leadership that convene on a regular basis to receive updates from our committees, cybersecurity management, external
+Added: professional advisors, and other relevant Company personnel about the Cybersecurity and Privacy programs we have in place;
+Added: discuss and assess material risks and planned risk mitigation, incidents and planned remediation efforts, trends observed,
+Added: consider cybersecurity-related proposals, and review and adopt changes in cybersecurity policies.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.