4 unchanged sentences
At Cars Commerce, we believe cybersecurity risk management is of the utmost importance.
−Removed: As a result, Cars Commerce has implemented an information security management system (the “ISMS”) designed to protect our infrastructure from potential threats and is designed to allow us to assess, identify and manage material risks from cybersecurity threats as described in more detail below.
+Added: As a result, Cars Commerce has implemented an information security management system (the "ISMS") designed to protect our infrastructure from potential threats and to allow us to assess, identify and manage material risks from cybersecurity threats as described in more detail below.
The ISMS supports the security safeguards that are designed to protect the confidentiality, integrity, availability, and contractual compliance of the Cars.com Inc.
2 unchanged sentences
In addition, we engage with external resources to contribute to, and provide independent evaluation of, our existing cybersecurity practices.
−Removed: As a result, in 2023, Cars Commerce engaged an independent auditor to conduct an audit of the ISMS.
−Removed: As a result of the independent audit, in December 2023, Cars Commerce completed the certification to meet International Organization for Standardization 27001 requirements for the above-stated entities.
−Removed: In October 2023, Cars Commerce, through its subsidiary, completed the acquisition of D2C Media Inc.
−Removed: ("D2C Media").
−Removed: During the due diligence, Cars Commerce completed a robust evaluation of its cybersecurity risk management process and plans to integrate D2C Media into the ISO Certification Process.
+Added: As a result, in 2023, Cars Commerce engaged an independent auditor to conduct an audit of the ISMS, and Cars Commerce completed the certification to meet International Organization for Standardization 27001 requirements for the above-stated entities.
+Added: In October 2024, Cars successfully completed its ISO 27001 surveillance audit.
+Added: In November 2023, Cars Commerce, through its subsidiary, completed the acquisition of D2C Media.
+Added: During the due diligence, Cars Commerce completed an evaluation of its cybersecurity risk management process and plans to integrate D2C Media into the ISO 27001 certification process.
Our employees are the first line of defense against cybersecurity incidents.
As such, employees receive annual security awareness training to understand the behaviors and technical requirements necessary to protect information.
−Removed: We also conduct periodic phishing awareness exercises to educate employees to recognize and report suspicious activity.
+Added: We also conduct annual phishing awareness exercises to educate employees to recognize and report suspicious activity.
We also use a combination of tools and in-house technologies to protect Cars Commerce, our employees and our customers, including but not limited to using only SOC 2 compliant hosting providers, anti-malware software, intrusion prevention systems, network and web application firewalls, multi-factor authentication, encryption, and remote access via virtual private network ("VPN") software.
9 unchanged sentences
Cars Commerce employees are also responsible for reporting any suspected cybersecurity or information security event that they observe or experience as soon as possible, by either contacting the Cars Commerce helpdesk, or the Information Security Team directly.
−Removed: The Information Security Team then creates a Security Incident Response Team (“SIRT”) which, depending on the incident, comprises of the cybersecurity staff, Systems and Network Engineers, the Chief Technology Officer and the Chief Legal Officer, or other stakeholders as appropriate.
+Added: The Information Security Team then creates a Security Incident Response Team ("SIRT") which, depending on the incident, is comprised of cybersecurity staff, Systems and Network Engineers, the Chief Technology Officer and the Chief Legal Officer, or other stakeholders as appropriate.
The SIRT investigates and manages the impact of cybersecurity incidents in accordance with the security incident response procedures.
1 unchanged sentence
The report includes information about the incident, details about the response and includes recommendations to prevent similar security events from occurring in the future.
−Removed: Additionally, the Information Security Team provides the Audit Committee and the Board with regular updates on cybersecurity matters, including recent cybersecurity threats and incidents and ongoing efforts to prevent, detects and respond to internal and external cybersecurity threats.
+Added: Additionally, the Information Security Team provides the Audit Committee and the Board with regular updates on cybersecurity matters, including recent cybersecurity threats and incidents and ongoing efforts to prevent, detect and respond to internal and external cybersecurity threats.
As of the date of this Report, we are not aware of any risks from cybersecurity threats, including as a result of any previous cybersecurity incidents, that have materially affected, or are reasonably likely to materially affect, Cars Commerce, including our business strategy, results of operations or financial condition.
−Removed: However, there can be no assurance that our cybersecurity prevention and mitigation efforts have been or will continue to prevent possible cybersecurity threats or whether a cybersecurity threat could have a material adverse effect on our business strategy, results of operations or financial condition.
+Added: However, there can be no assurance that our cybersecurity prevention and mitigation efforts have been or will continue to prevent possible cybersecurity threats or whether a cybersecurity threat could have a material adverse
+Added: effect on our business strategy, results of operations or financial condition.
See "Risks Related to Technology" in "Risk Factors" of this Report.
−Removed: In July 2023, the SEC adopted rules requiring the disclosure of material cybersecurity incidents.
−Removed: To ensure compliance with the SEC requirement, Cars Commerce has a review process to determine whether the impact of a cybersecurity threat is material and requires
−Removed: disclosure of the cybersecurity incident.
+Added: The SEC adopted rules requiring the disclosure of material cybersecurity incidents.
+Added: To ensure compliance with the SEC requirement, Cars Commerce has a review process to determine whether the impact of a cybersecurity threat is material and requires disclosure of the cybersecurity incident.
In compliance with the SEC rule and Cars Commerce’s process, if such a cybersecurity incident occurs and the appropriate representatives from the Information Security Governance Committee determine that the cybersecurity incident is material, Cars Commerce will make the appropriate disclosures in a Current Report on Form 8-K within the required timeframe.
1 unchanged sentence
The Board has delegated direct cybersecurity and information security risk oversight to the Audit Committee.
−Removed: Cars Commerce management provides the Audit Committee with regular updates at least quarterly regarding the effectiveness of Cars Commerce’s overall cybersecurity program and other cyber security related matters, which may include, Cars Commerce’s inherent cybersecurity risks, updates on recent cybersecurity threats and incidents, policies and practices, industry trends, regulatory developments, threat environment and vulnerability assessments and specific and ongoing efforts to prevent, detect and respond to internal and external cybersecurity threats.
+Added: Cars Commerce management provides the Audit Committee with regular updates at least quarterly regarding the effectiveness of Cars Commerce’s overall cybersecurity program and other cybersecurity related matters, which may include, Cars Commerce’s inherent cybersecurity risks, updates on recent cybersecurity threats and incidents, policies and practices, industry trends, regulatory developments, threat environment and vulnerability assessments and specific and ongoing efforts to prevent, detect and respond to internal and external cybersecurity threats.
The Chair of the Audit Committee informs the Board of the outcome of these meetings through updates presented to the Board at regularly scheduled Board meetings.
At the management level, our CEO provides general management, oversight and mitigation of Cars Commerce’s risk.
−Removed: The Chief Legal Officer and the Chief Technology Officer are the key executives responsible for managing Cars Commerce’s Information Security function and ensuring that Cars Commerce’s information security processes comply with applicable laws, SEC requirements and contractual obligations respectively.
−Removed: Cars Commerce’s Information Security Team, in conjunction with the Information Security Governance Committee are responsible for assessing and managing material risks from cybersecurity threats and providing management direction and support for information security.
+Added: Our Chief Technology Officer and Senior Vice President of Information Security manage Cars Commerce’s Information Security function.
The Information Security Team is composed of skilled professionals with relevant information and cybersecurity education, certifications and experience.
−Removed: The Information Security Team coordinates the Cars Commerce Information Security Governance Committee, comprised of senior business leaders who support Cars Commerce’s Information Security Management System based on their area of expertise.
+Added: The Information Security Team coordinates with the Cars Commerce Information Security Governance Committee, comprised of senior business leaders who support Cars Commerce’s Information Security Management System based on their area of expertise.
+Added: Cars Commerce’s Information Security Team, in conjunction with the Information Security Governance Committee, assesses and manages material risks from cybersecurity threats and provides management direction and support for information security.
Working together the teams initiate and control the implementation and operation of information security within Cars Commerce.
−Removed: We maintain administrative offices and other facilities to support our operations.
−Removed: We have a lease for our principal executive office in Chicago, Illinois.
−Removed: In 2023, we ceased operations at our Naperville, Illinois office and terminated the lease effective February 2024.
+Added: We do not own any material real property.
+Added: Our principal executive offices are located in Chicago, Illinois.
+Added: We also lease a production studio in Chicago, Illinois and administrative offices in Canada.
+Added: We terminated our Naperville, Illinois office lease effective February 2024.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.