4 unchanged sentences
We have established processes for identifying, assessing and managing material risks from cybersecurity threats associated with our key information technology systems.
−Removed: These processes have been integrated into our overall risk management strategies, as overseen by our Board of Directors, primarily through the board's Corporate Risk Committee and Audit Committee.
+Added: These processes have been integrated into our overall risk management strategies, as overseen by our Board of Directors, primarily through the Corporate Risk Committee and Audit Committee.
These processes also include identifying and overseeing risks from cybersecurity threats associated with the use of third-party service providers.
8 unchanged sentences
The CIO and CISO are also supported by an incident response team ("IRT") comprised of selected members of senior management and responsible for providing cross-functional support and response facilitation for cybersecurity incidents.
−Removed: Our CISO oversees our cybersecurity incident response plan and related processes that are designed to assess and manage material risks from cybersecurity threats, including aligning programs with industry standards, conducting tabletop
−Removed: exercises, providing education/training and taking other preventive measures.
+Added: Our CISO oversees our cybersecurity incident response plan and related processes that are designed to assess and manage material risks from cybersecurity threats, including aligning programs with industry standards, conducting tabletop exercises, providing education/training and taking other preventive measures.
Our CISO coordinates with legal counsel and third-party experts to assess and manage material risks from cybersecurity threats.
9 unchanged sentences
Additionally, the Audit Committee of our Board of Directors oversees adequacy and effectiveness of our controls and procedures, including those designed to assess, identify and manage material risks from cybersecurity threats and incidents.
−Removed: Further, at least once per quarter, our CIO and/or CISO report on cybersecurity matters to the Corporate Risk Committee, and updates are provided to our Board of Directors at regular board meetings.
+Added: Further, at least bi-annually, our CIO and/or CISO report on cybersecurity matters to the Corporate Risk Committee, and updates are provided to our Board of Directors at regular board meetings.
The CIO also provides updates annually or more frequently as appropriate to our Board of Directors.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.