3 unchanged sentences
At BJ’s, we recognize the importance of information security practices designed to protect the confidentiality, integrity, and availability of company information and the personal information that our members share with us.
−Removed: We have implemented a cybersecurity program in accordance with our risk profile and business that is informed by recognized industry standards and frameworks, and incorporates elements of the same, including elements of the National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”), International Organization for Standardization (“ISO”) 27001 and Payment Card Industry Data Security Standard (“PCI DSS”) standards.
+Added: We have implemented a cybersecurity program in accordance with our risk profile and business that is informed by recognized industry standards and frameworks, and incorporates elements of the same, including elements of the National Institute of Standards and Technology
+Added: Cybersecurity Framework (“NIST CSF”), International Organization for Standardization (“ISO”) 27001 and Payment Card Industry Data Security Standard (“PCI DSS”) standards.
Our cybersecurity risk assessment program includes a number of components, including information security program assessments, audits and maturity assessments, that are conducted periodically by both internal and external resources.
−Removed: Additionally, we partner with multiple third-party managed security service providers for enhanced monitoring of our
−Removed: information technology and data security environment and to perform proactive detection and investigation of malicious activity within our network.
+Added: Additionally, we partner with multiple third-party managed security service providers for enhanced monitoring of our information technology and data security environment and to perform proactive detection and investigation of malicious activity within our network.
Our internal audit function also conducts regular assessments of different systems to provide the audit committee with information on our cybersecurity risk management processes, which processes are integrated into our overall enterprise risk management program.
6 unchanged sentences
Governance Related to Cybersecurity Risks
−Removed: Our Chief Information Officer (“CIO”) is responsible for the strategic leadership and direction of the Company’s information technology organization.
−Removed: Prior to joining BJ’s in 2023, our current CIO served as global chief information officer at a public healthcare company, where she led information technology, privacy assurance, cyber, digital and data security across key business units.
−Removed: She has also held various chief information officer and technology leadership roles at several other healthcare companies and a multinational pharmaceutical corporation, along with other senior management positions during her career.
−Removed: The CIO and the VP of IT Security and Compliance regularly report to senior management and the board on the governance aspects of our data security program.
−Removed: The CIO and the VP of IT Security and Compliance are also members of our information security steering committee, which is comprised of executives throughout the Company who oversee areas such as finance, operations, legal, human resources, strategy and development, digital, and commercial.
+Added: Our c hief information and digital officer (“CIDO”) is responsible for the strategic leadership and direction of the Company’s information technology organization.
+Added: While at BJ’s, our current CIDO served as our chief digital officer and was responsible for our e-commerce and digital strategies.
+Added: Prior to joining BJ’s in 2020, she served as vice president of online merchandising for a large home improvement retailer.
+Added: She has also held various technology leadership roles at several other retail companies where she oversaw digital operations, including information security and data protection matters, along with other senior management positions during her career.
+Added: The CIDO and the VP of IT security and compliance regularly report to senior management and the board on the governance aspects of our data security program.
+Added: The CIDO and the VP of IT security and compliance are also members of our information security steering committee, which is comprised of executives throughout the Company who oversee areas such as finance, operations, legal, human resources, strategy and development, digital, and commercial.
This committee meets regularly to, as relevant, discuss oversight of the Company’s cybersecurity program, program enhancements and new risks or threats that the Company might be facing.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.