10 unchanged sentences
We regularly engage with outside experts to assess the maturity of our organizational security program and to inform our short- and long-term cybersecurity strategy.
−Removed: We routinely test and improve our information systems through security and risk and compliance reviews and user education campaigns and other strategies.
−Removed: We also subscribe to various threat intelligence feeds and are active in the information security community.
−Removed: We maintain an Information Security Policy, which details the acceptable processes and practices our associates must follow to protect the interests of the Company, our customers and other parties.
+Added: We maintain a comprehensive cybersecurity program designed to protect the confidentiality, integrity, and availability of our data, systems, and networks.
+Added: Our security framework is based on a defense-in-depth strategy, employing multiple layers of security controls to mitigate risks associated with cyber threats.
Key components of the Information Security Program include:
−Removed: ● Acknowledgement of the Information Security Policy upon hire and annually thereafter;
−Removed: ● Access controls, including identification, authentication, logging and authorization;
−Removed: ● Endpoint detection and response;
−Removed: ● Data classification and labeling;
−Removed: ● Privileged Identity Management
−Removed: ● Security Awareness training and a Cybersecurity Ambassador Program;
−Removed: ● A Cybersecurity Incident Response Plan, including procedures for responding to cybersecurity incidents and a framework for evaluating the materiality of the incident for disclosure and reporting purposes.
+Added: ● Network and Endpoint Security:
+Added: Firewalls, intrusion prevention systems, endpoint detection and response solutions, and monitoring and alerting.
+Added: ● Access Controls and Authentication:
+Added: Multi-factor authentication, least-privilege access principles, role-based access controls and privileged identity management .
+Added: ● Data Protection:
+Added: Encryption of sensitive data in transit and at rest, data loss prevention tools, data classification and labeling, and secure backup solutions.
+Added: ● Incident Response:
+Added: An incident response plan aligned with industry-best practices and a framework for evaluating the materiality of the incident for disclosure and reporting purposes.
+Added: ● Compliance and Governance:
+Added: Adherence to regulatory requirements, third-party risk management and routine security audits.
+Added: ● Security Awareness and Training:
+Added: Regular employee training, phishing simulations and a Cybersecurity Ambassador program.
+Added: We leverage our information sharing relationship with the Federal Bureau of Investigation, Cybersecurity and Infrastructure Agency and local law enforcement, as well as additional threat intelligence information, to continuously assess and enhance our cybersecurity posture to address emerging threats and minimize potential impacts on our operations, customers and stakeholders.
The Audit Committee of our Board of Directors is responsible for oversight of our cybersecurity program.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.