10 unchanged sentences
Such contractual terms include requirements to provide notification of cyber incidents involving our systems or data and requirements to provide industry-accepted disclosures, such as SOC 2 Type II reports, on a regular basis.
−Removed: We utilize several cybersecurity processes, technologies, and controls to aid in our efforts to assess, identify, and manage material risks from cybersecurity threats, and to protect against, detect and respond to cybersecurity incidents (as defined in Item 106(a) of Regulation S-K), including, among others, the following:
−Removed: • maintain a global Security Operations Center to support visibility to cybersecurity incidents in real time;
+Added: We utilize several cybersecurity tactics, techniques, processes and controls to aid in our efforts to assess, identify, and manage material risks from cybersecurity threats, and to protect against, detect and respond to cybersecurity incidents (as defined in Item 106(a) of Regulation S-K), including, among others, the following:
+Added: • maintain a Security Operations Center to support visibility to cybersecurity incidents in real time;
• require all salaried employees to complete an annual cybersecurity training program where specific threats and scenarios are highlighted based on our analysis of current risks to the organization;
6 unchanged sentences
Governance of cybersecurity risk management
−Removed: The Board of Directors, as a whole, has oversight responsibility for our strategic and operational risks.
+Added: Our Board of Directors, as a whole, has oversight responsibility for our strategic and operational risks.
Management is responsible for day-to-day assessment and management of cybersecurity risks.
−Removed: The IT Steering Committee, comprised of a cross-functional group of our executive management, leads management's oversight of the IT function, including IT risk management.
+Added: The IT Executive Steering Committee, comprised of a cross-functional group of our executive management, leads management's oversight of the IT function, including IT risk management.
+Added: The IT Steering Committee, comprised of operational management, provides tactical oversight of the IT function, including IT risk management
Our Director of IT has primary oversight of material risks from cybersecurity threats.
−Removed: Our Director of IT has 20 years of experience across various software engineering, IT security and compliance, business and management roles, including serving as the Director of Engineering Applications and Data Management, leading the development and implementation of information technology strategies and roadmaps for Digital and Engineering applications group.
+Added: Our Director of IT has 20 years of experience across various software engineering, IT security and compliance, business and management roles, including
+Added: serving as the Director of Engineering Applications and Data Management, leading the development and implementation of information technology strategies and roadmaps for Digital and Engineering applications group.
The Director of IT is supported by our Director of IT Security and Compliance, who has more than 10 years of experience in information technology and IT security.
−Removed: Our Director of IT and Director of IT Security and Compliance assess our cybersecurity readiness through internal assessment tools as well as third-party control tests, vulnerability assessments, audits and evaluation against industry standards.
−Removed: We have governance and compliance structures that are designed to elevate potential threats or vulnerabilities relating to cybersecurity to our Director of IT and IT Steering Committee.
+Added: Our Director of IT and Manager of IT Cybersecurity, Compliance and Data Privacy assess our cybersecurity readiness through internal assessment tools as well as third-party control tests, vulnerability assessments, audits and evaluation against industry standards.
+Added: We have governance and compliance structures that are designed to elevate potential threats or vulnerabilities relating to cybersecurity to our Director of IT, IT Steering Committee and IT Executive Steering Committee.
We also employ various defensive and continuous monitoring techniques using recognized industry frameworks and cybersecurity standards.
Our Director of IT meets with the IT Steering Committee monthly to review our information technology systems and discuss key cybersecurity risks.
−Removed: In addition, quarterly the Director of IT reviews our entire risk management program, which includes cybersecurity risks, with Executive management and the Board of Directors.
+Added: In addition, quarterly the Director of IT reviews our entire risk management program, which includes cybersecurity risks, with the IT Executive Steering Committee and the Board of Directors .
Material cybersecurity risks, threats & incidents
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.