20 unchanged sentences
We provide regular mandatory training for personnel regarding cybersecurity threats, which reinforces our information security policies, standards and practices, and such training is scaled to reflect the roles, responsibilities and information systems access of such personnel.
−Removed: We also publish an internal newsletter on a monthly and ad-hoc basis for enterprise-wide consumption to promote awareness of trends in cybersecurity threats and attack techniques.
+Added: We also publish an internal cybersecurity newsletter on an ad-hoc basis for enterprise-wide consumption to promote awareness of trends in cybersecurity threats and attack techniques.
• Incident Response and Recovery Planning:
−Removed: We have established and maintain comprehensive incident response and recovery plans that fully address our response to and recovery from a cybersecurity incident, and such plans are tested and evaluated on a periodic basis.
+Added: We have established and maintain comprehensive incident response and recovery plans that address our response to and recovery from a cybersecurity incident, and such plans are tested and evaluated on a periodic basis.
• Communication, Coordination and Disclosure:
We take a cross-functional approach to address the risk from cybersecurity threats, involving management personnel from our technology, operations, legal, internal audit and other key business functions and engage with our Board in an ongoing dialogue regarding cybersecurity threats and incidents while also implementing controls and procedures for the assessment and escalation of cybersecurity incidents pursuant to established thresholds so that decisions regarding the disclosure and reporting of such incidents can be made by management in a timely manner.
−Removed: Our Board regularly interacts with our Chief Information Security Officer and other members of management on cybersecurity risk management.
−Removed: A key part of our strategy for managing risks from cybersecurity threats is the ongoing assessment and testing of our processes and practices through auditing, assessments, tabletop exercises, vulnerability testing, and other exercises focused on evaluating our cybersecurity measures effectiveness.
+Added: • Governance:
+Added: Our Board regularly interacts with our Chief Information Security Officer ("CISO") and other members of management on cybersecurity risk management.
+Added: A key part of our strategy for managing risks from cybersecurity threats is the ongoing assessment and testing of our processes and practices through auditing, assessments, tabletop exercises, vulnerability testing, and other exercises focused on evaluating the effectiveness of our cybersecurity measures.
We regularly engage third parties to perform assessments of our cybersecurity program, including information security maturity assessments, audits and independent reviews of our information security control environment and operating effectiveness.
3 unchanged sentences
Our Board also receives prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding such incident until it has been addressed.
−Removed: At least quarterly, the Board discusses the Company’s approach to cybersecurity risk management with our Chief Information Security Officer ("CISO").
+Added: At least quarterly, the Board discusses the Company’s approach to cybersecurity risk management with our CISO.
Our CISO is the member of our management team that is principally responsible for overseeing our cybersecurity program, in partnership with other business leaders across the Company.
11 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.