2 unchanged sentences
Risk Management and Strategy
−Removed: Constellation has established programs and processes to manage material risks from cybersecurity threats including assessing and identifying existing cybersecurity risks, as well as continuously monitoring for developing risks.
+Added: We have established technical systems programs and processes to manage material risks from cybersecurity threats including assessing and identifying existing cybersecurity risks, as well as continuously monitoring for developing risks.
Our cybersecurity risk management strategy is established at the executive level and is implemented through our cybersecurity program which deploys risk-based security controls and services to protect our customers, personnel, information and cyber assets.
The program aligns enterprise cyber and physical security controls with the National Institute of Standards & Technology (NIST) Cybersecurity Framework (CSF) and other industry standards such as the NERC and NRC cybersecurity standards.
−Removed: Our cybersecurity program is aligned to
−Removed: the five functions of the NIST Cybersecurity Framework – identify, detect, protect, respond, and recover.
+Added: Our cybersecurity program is aligned to the five functions of the NIST Cybersecurity Framework – identify, detect, protect, respond, and recover.
Cybersecurity risk is assessed and reported in our enterprise risk management program, which utilizes the Three Lines Model adapted from the Institute of Internal Auditors, for risk management to assign clear risk responsibilities across the enterprise.
1 unchanged sentence
At the highest level, our program includes multi-layered oversight by the Board of Directors and Board Committees.
−Removed: Our cybersecurity and physical security controls are implemented through policies and procedures we utilize for planning, performing, managing, assessing, innovating, and improving our security controls.
+Added: Our cybersecurity and physical security controls are implemented through technical systems, policies and procedures we utilize for planning, performing, managing, assessing, innovating, and improving our security controls.
To protect our information and cyber assets, we implement practices for training and screening of personnel, access management, network defense, asset configuration management, vulnerability assessment (including penetration testing), third-party security, and privacy and information protection.
2 unchanged sentences
To assist in detecting cybersecurity events, we deploy security logging and monitoring, malicious code detection, and data loss protection tools.
−Removed: If the company is the target of a cybersecurity attack, we have established processes for incident response and crisis management to triage potential incidents, determine severity, contain, and eradicate a threat.
+Added: If we are the target of a cybersecurity attack, we have established processes for incident response and crisis management to triage potential incidents, determine severity, contain, and eradicate a threat.
These processes require notifications to regulatory and other governmental authorities of cybersecurity events as required by law, including providing notice to investors for material cybersecurity events.
−Removed: To recover our systems and information, we utilize established system recovery plans and business continuity plans.
+Added: To recover our systems and information, we utilize established system recovery plans, data and configuration backup strategies, and business continuity plans.
As part of our process to continuously improve, we utilize our internal audit, risk, and legal functions to evaluate security controls and risk management practices.
7 unchanged sentences
Our Chief Information Officer (CIO) and Chief Information Security Officer (CISO) provide regular reports to the Board, or one or both of its designated Committees, regarding the security of our operational and information technology programs, systems, and risks.
−Removed: We also report on the state of our cybersecurity program and provide key risk indicators to track performance.
+Added: We also report on the state of our cybersecurity program, provide key risk indicators to track performance, and schedule additional informational sessions on cybersecurity practices, as needed.
Emergent matters or events are reported to the Board between scheduled meetings on an ad hoc basis through our incident response and crisis management protocols.
−Removed: At the executive and management level, the Chief Administration Officer, via delegations to the Cyber Security organization, is authorized to govern and functionally oversee our security controls and services on behalf of the enterprise.
+Added: At the executive and management level, the Chief Administration Officer, via delegations to the cybersecurity organization, is authorized to govern and functionally oversee our security controls and services on behalf of the enterprise.
Our cybersecurity organization, under the direction of the CISO who reports to the CIO, implements and provides governance and functional oversight for cybersecurity controls and services, including coordination with our corporate security function.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.