6 unchanged sentences
While the Board is ultimately responsible for risk oversight, the Audit Committee oversees the overall review of our policies and procedures with respect to risk assessment and risk management, and has oversight of information technology and security matters, which includes cybersecurity strategies and risks, as well as data privacy and data protection (Information Security).
−Removed: The Audit Committee oversees
−Removed: the management of risks from cybersecurity threats, including the policies, processes, and practices that the Company’s management implements to address risks from cybersecurity threats.
−Removed: On a quarterly basis, our Chief Information Officer (CIO) and Chief Information Security Officer (CISO) report to the Audit Committee on our Information Security program, including presentations and reports on cybersecurity risks, which address a wide range of topics including, for example, recent developments, security initiatives, vulnerability assessments, the threat environment, technological trends, and information security considerations arising with respect to the Company’s peers and vendors;
+Added: The Audit Committee oversees the management of risks from cybersecurity threats, including the policies, processes, and practices that the Company’s management implements to address risks from cybersecurity threats.
+Added: On a quarterly basis, our Chief Information Officer (CIO) and Chief Information Security Officer (CISO) report to the Audit Committee on our Information Security program, including presentations and reports on cybersecurity risks, which address a wide range of topics including, for example, recent developments, security initiatives, vulnerability assessments, the threat environment,
+Added: technological trends, and information security considerations arising with respect to the Company’s peers and vendors;
recent cybersecurity-related developments;
14 unchanged sentences
Risk Management
−Removed: We have created a cybersecurity program that endeavors to prevent, detect, contain and respond to material risks from cybersecurity threats and incidents and integrate cybersecurity risk into our enterprise risk management framework and activities.
−Removed: Our program consists of policies and procedures for identification, assessment, remediation, response, and reporting of cybersecurity threats and incidents.
−Removed: The cybersecurity program is a part of our company’s ERM framework and activities.
−Removed: The cybersecurity program employs a risk-based approach and draws upon a combination of industry standard frameworks, including the National Institute of Standards and Technology (NIST) Cybersecurity Framework and the Payment Card Industry Data Security Standard (PCI DSS).
+Added: We have established a cybersecurity risk management program designed to prevent, detect, contain, and respond to material risks from cybersecurity threats and incidents.
+Added: Cybersecurity risk is integrated into the Company’s enterprise risk management (“ERM”) framework and considered alongside other enterprise risks in business and strategic decision‑making.
+Added: The program consists of policies, procedures, and supporting technical and organizational measures for identification, assessment, remediation, response, and reporting of cybersecurity threats and incidents.
+Added: The cybersecurity program employs a risk‑based approach and draws upon elements of recognized industry frameworks, including the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework and the Payment Card Industry Data Security Standard (“PCI DSS”), which are applied in a manner tailored to the Company’s risk profile and business operations.
Our cybersecurity risk management approach and processes are designed to manage risks from cybersecurity threats associated with our use of third-party service providers, ranging from vendor cyber vetting to conducting security assessments and monitoring activities.
17 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.