17 unchanged sentences
Multi-factor authentication, least-privilege access principles, role-based access controls and privileged identity management
+Added: ● Asset Management:
+Added: Maintain the inventory of hardware, software, and cloud resources;
+Added: assigns clear ownership and manages assets throughout their lifecycle from acquisition to secure disposal
+Added: ● Vulnerability and Patch Management:
+Added: Continues internal and external vulnerability scanning, patch management with defined service level agreements, and annual penetration testing conducted by a qualified 3 rd party
● Data Protection:
5 unchanged sentences
● Security Awareness and Training:
−Removed: Regular employee training, phishing simulations and a Cybersecurity Ambassador program.
+Added: Annual employee training, ongoing phishing simulations and a Cybersecurity Ambassador program
We leverage our information sharing relationship with the Federal Bureau of Investigation, Cybersecurity and Infrastructure Agency and local law enforcement, as well as additional threat intelligence information, to continuously assess and enhance our cybersecurity posture to address emerging threats and minimize potential impacts on our operations, customers and stakeholders.
The Audit Committee of our Board of Directors is responsible for oversight of our cybersecurity program.
−Removed: In addition, the Technology and Digital Commerce Committee, which was established in 2022, assists the Board of Directors with its oversight responsibilities regarding the role of technology, data, digital commerce and the Company’s ability to understand and connect with its consumers in executing the Company’s strategies, business plans and operational requirements.
+Added: In addition, the Technology and Digital Commerce Committee assists the Board of Directors with its oversight responsibilities regarding the role of technology, data, digital commerce and the Company’s ability to understand and connect with its consumers in executing the Company’s strategies, business plans and operational requirements.
On a quarterly basis, our CIO updates the Audit Committee on the Company’s cybersecurity program, including, among other items, actual events or incidents, results of vulnerability assessments and penetration testing.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.