22 unchanged sentences
CIM Group’s internal processes require escalation of material cybersecurity risks to its management and its Cybersecurity Committee (the “Committee”) for evaluation.
−Removed: The Committee consists of CIM Group’s Chief Technology Officer (the “CTO”) , CIM Group’s Chief Compliance Officer (the “CCO”) and representatives from CIM Group’s operations, compliance and accounting departments.
+Added: The Committee consists of CIM Group’s Head of Enterprise Technology, CIM Group’s Chief Compliance Officer (the “CCO”), CIM Group’s Head of Transformation and representatives from CIM Group’s operations, technology, and compliance departments as needed.
The Committee is responsible for CIM Group’s cybersecurity policy and overseeing the activities of CIM Group’s cybersecurity practices, including assessing CIM Group’s risks and controls.
−Removed: The Committee is chaired by the CTO and has more than 30 years of experience in the fields of information technology, cybersecurity and adjacent roles, including serving on cybersecurity advisory councils.
−Removed: In addition, members of the Committee has relevant industry experience in enterprise risk management and compliance.
−Removed: The team responsible for developing and implementing our cybersecurity program collectively holds an MS in Cybersecurity and Information Assurance and have multiple cybersecurity certifications, including CRISC, CISM, CISA, NCSP-NIST, CISSP, CASP+, CySA+ and Security+.
−Removed: The Committee has established a Cybersecurity Subcommittee (the “Subcommittee”).
−Removed: The Subcommittee consists of, among other individuals, the CCO, the CTO, the chief financial officers of public companies that are subject to the SEC’s cybersecurity rule adopted in 2023 and are managed by CIM Group, including our Chief Financial Officer.
−Removed: The Subcommittee is tasked with assisting CIM Group-managed public companies (that are subject to the SEC’s cybersecurity rules adopted in 2023), including us, in complying with such cybersecurity rules.
−Removed: The Committee and Subcommittee each conduct both regular quarterly and as-needed meetings throughout the year during which members of the CIM Group’s IT Department provide updates and report on meaningful cybersecurity risks, threats, incidents and vulnerabilities in accordance with the Committee’s and the Subcommittee’s respective reporting frameworks, as well as related priorities, mitigation and remediation activities, financial and employee resource levels,
−Removed: regulatory compliance, technology trends and third-party provider risks.
+Added: The Committee is chaired by CIM’s Head of Enterprise Technology and collectively the group has
+Added: more than 30 years of experience in the fields of information technology, cybersecurity and adjacent roles, including serving on cybersecurity advisory councils.
+Added: In addition, members of the Committee have relevant industry experience in enterprise risk management and compliance.
+Added: The Cybersecurity Committee is tasked with assisting CIM Group-managed public companies (that are subject to the SEC’s cybersecurity rules adopted in 2023), including us, in complying with such cybersecurity rules.
+Added: The Committee conducts both regular quarterly and as-needed meetings throughout the year during which members of the CIM Group’s IT Department provide updates and report on meaningful cybersecurity risks, threats, incidents and vulnerabilities in accordance with the Committee’s respective reporting frameworks, as well as related priorities, mitigation and remediation activities, financial and employee resource levels, regulatory compliance, technology trends and third-party provider risks.
To help inform this reporting framework, CIM Group maintains incident response plans and other policies and procedures designed to respond to, mitigate and remediate cybersecurity incidents based on the potential impact to CIM Group’s business, IT systems, network or data, including data held by third parties, or to the IT or other critical services provided by third-party vendors and service providers.
CIM Group’s personnel responsible for cybersecurity policy comprises of individuals with either formal education and degrees in IT or cybersecurity, or with experience working in IT and cybersecurity, including relevant industry experience in security related industries.
−Removed: We believe that the processes, policies and procedures established by the Committee and the Subcommittee provide guidance for consistent and effective incident handling and response and set standards for internal notifications and escalations, as well as external notification considerations with respect to a cybersecurity event or incident requiring disclosure or notification in accordance with applicable laws.
+Added: We believe that the processes, policies and procedures established by the Committee provide guidance for consistent and effective incident handling and response and set standards for internal notifications and escalations, as well as external notification considerations with respect to a cybersecurity event or incident requiring disclosure or notification in accordance with applicable laws.
Board of Directors Oversight of Cybersecurity Risk Management
1 unchanged sentence
The Audit Committee receives quarterly updates from CIM Group with respect to the effectiveness of its cyber readiness and cybersecurity program.
−Removed: This oversight includes briefing and a report by the CTO or CIM Group’s Head of Transformation, as well as a discussion of any cybersecurity breaches detected by CIM Group and a summary of, among other things, the current cybersecurity threat landscape, defensibility measures implemented by CIM Group, the health of CIM Group’s information security system, effectiveness of CIM Group’s cybersecurity controls and recoverability and business continuity testing.
+Added: This oversight includes briefing and a report by CIM Group’s Head of Transformation or CIM Head of Enterprise Technology, as well as a discussion of any cybersecurity breaches detected by CIM Group and a summary of, among other things, the current cybersecurity threat landscape, defensibility measures implemented by CIM Group, the health of CIM Group’s information security system, effectiveness of CIM Group’s cybersecurity controls and recoverability and business continuity testing.
Pursuant to the Company’s cybersecurity policy, the Audit Committee will be promptly notified of any material cybersecurity incident required to be disclosed under Item 1.05 on a Current Report on Form 8-K and shall oversee the Company’s response to such matter.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.