13 unchanged sentences
and management oversight to assess, identify and manage material risks from cybersecurity threats.
−Removed: CIM Group’s controls leverage the National Institute of Standards and Technology Cybersecurity
+Added: CIM Group’s controls leverage the National Institute of Standards and Technology Cybersecurity Framework.
CIM Group also utilizes industry and government associations, the results from regular internal and third-party audits and other similar resources to inform its cybersecurity processes and to allocate resources.
11 unchanged sentences
The team responsible for developing and implementing our cybersecurity program collectively holds an MS in Cybersecurity and Information Assurance and have multiple cybersecurity certifications, including CRISC, CISM, CISA, NCSP-NIST, CISSP, CASP+, CySA+ and Security+.
−Removed: The Committee has established a Cybersecurity Subcomittee (the “Subcommittee”).
+Added: The Committee has established a Cybersecurity Subcommittee (the “Subcommittee”).
The Subcommittee consists of, among other individuals, the CCO, the CTO, the chief financial officers of public companies that are subject to the SEC’s cybersecurity rule adopted in 2023 and are managed by CIM Group, including our Chief Financial Officer.
The Subcommittee is tasked with assisting CIM Group-managed public companies (that are subject to the SEC’s cybersecurity rules adopted in 2023), including us, in complying with such cybersecurity rules.
−Removed: The Committee and Subcommittee each conduct both regular quarterly and as-needed meetings throughout the year during which members of the CIM Group’s IT Department provide updates and report on meaningful cybersecurity risks, threats, incidents and vulnerabilities in accordance with the Committee’s and the Subcommittee’s respective reporting frameworks, as well as related priorities, mitigation and remediation activities, financial and employee resource levels, regulatory compliance, technology trends and third-party provider risks.
+Added: The Committee and Subcommittee each conduct both regular quarterly and as-needed meetings throughout the year during which members of the CIM Group’s IT Department provide updates and report on meaningful cybersecurity risks, threats, incidents and vulnerabilities in accordance with the Committee’s and the Subcommittee’s respective reporting frameworks, as well as related priorities, mitigation and remediation activities, financial and employee resource levels,
+Added: regulatory compliance, technology trends and third-party provider risks.
To help inform this reporting framework, CIM Group maintains incident response plans and other policies and procedures designed to respond to, mitigate and remediate cybersecurity incidents based on the potential impact to CIM Group’s business, IT systems, network or data, including data held by third parties, or to the IT or other critical services provided by third-party vendors and service providers.
4 unchanged sentences
The Audit Committee receives quarterly updates from CIM Group with respect to the effectiveness of its cyber readiness and cybersecurity program.
−Removed: This oversight includes briefing and a report by the CTO or CIM Group’s Head of Operations, as well as a discussion of any cybersecurity breaches detected by CIM Group and a summary of, among other things, the current cybersecurity threat landscape, defensibility measures implemented by CIM Group, the health of CIM Group’s information security system,
−Removed: effectiveness of CIM Group’s cybersecurity controls and recoverability and business continuity testing.
+Added: This oversight includes briefing and a report by the CTO or CIM Group’s Head of Transformation, as well as a discussion of any cybersecurity breaches detected by CIM Group and a summary of, among other things, the current cybersecurity threat landscape, defensibility measures implemented by CIM Group, the health of CIM Group’s information security system, effectiveness of CIM Group’s cybersecurity controls and recoverability and business continuity testing.
Pursuant to the Company’s cybersecurity policy, the Audit Committee will be promptly notified of any material cybersecurity incident required to be disclosed under Item 1.05 on a Current Report on Form 8-K and shall oversee the Company’s response to such matter.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.