3 unchanged sentences
As a highly regulated global financial services company, we understand the substantial operational risks for companies in our industry as well as the importance of protecting the information and data of our clients, third parties and employees and the resilience of our systems.
−Removed: As such, our Global Informational Security (GIS) Program is designed and operated to mitigate information security risks and threats to the company.
+Added: As such, our GIS Program is designed and operated to mitigate information security risks and threats to the company.
Its intent is to safeguard the confidentiality, integrity and availability of our information and services.
2 unchanged sentences
We manage cybersecurity risk to the organization as part of our business strategy, risk management and financial functions in alignment with our overall Enterprise Risk Management Program and regularly engage with the risk committee of the board of directors and the board of directors as a whole regarding the effectiveness of the GIS Program and the management of our cybersecurity risks.
−Removed: The GIS Program is led by CME Group’s Chief Information Security Officer (CISO), who has worked in various roles in information security for over 20 years and has led our GIS Program for more than five years since joining the company in 2016 in a senior role in GIS.
+Added: Our GIS Program is led by the individual serving in the role of Chief Information Security Officer (CISO).
+Added: Our former CISO transitioned to a new role at another company.
+Added: We have appointed an interim CISO while we complete our search for a permanent replacement.
+Added: Our interim CISO has over 25 years of technology experience and 22 years as a senior leader within CME Group's information security operations and incident response program.
The CISO reports to our Chief Information Officer (CIO), a member of our Management Team.
−Removed: Our GIS team is comprised of over 200 full-time employees, many of whom hold cybersecurity, risk, or management certifications, such as Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, Series 99, Certified Information Systems Auditor, Project Management Professional, various cloud provider certifications and various levels of ITIL certifications.
−Removed: As part of our GIS Program, CME Group operates a Cyber Defense Center that virtually links 24/7 to our international cybersecurity teams and serves as a global hub for cybersecurity risk management activities, including log collection, event monitoring, threat detection and incident response, resiliency, operations, vulnerability management and the proactive collection and processing of both open source and proprietary threat and intelligence feeds allowing the company to efficiently manage, investigate and respond to cybersecurity events.
+Added: Our GIS team is comprised of over 250 full-time employees, many of whom hold cybersecurity, risk, or management certifications, such as Certified Information Systems Security Professional, Certified Information Security Manager, Certified in Risk and Information Systems Control, Series 99, Certified Information Systems Auditor, Project Management Professional, various cloud provider certifications and various levels of certifications demonstrating expertise in technology infrastructure.
+Added: A s part of our GIS Program, CME Group operates a Cyber Defense Center that virtually links 24/7 to our international cybersecurity teams and serves as a global hub for cybersecurity risk management activities, including log collection, event monitoring, threat detection and incident response, resiliency, operations, vulnerability management and the proactive collection and processing of both open source and proprietary threat and intelligence feeds allowing the company to efficiently manage, investigate and respond to cybersecurity events.
Our GIS team conducts analyses and aims to prevent, detect and respond to systemic events that might threaten our company, industry or the economy.
−Removed: The GIS Program includes a Cyber Defense team, which manages the Incident Response Plan (IRP), and consists of subject matter experts from GIS and Information Governance, who work together to monitor and respond to cybersecurity incidents.
−Removed: The IRP outlines our cyber and incident response policies and governs our incident response lifecycle, which divides overall incident response into serial phases.
−Removed: The Crisis Management Team (CMT) is responsible for oversight during an incident, in conjunction with the Cyber Coordination Team (CCT).
−Removed: The CCT manages responses to cybersecurity and compliance incidents, collaborating with subject matter experts from various departments in response to specific incidents.
−Removed: When an incident reaches a certain threshold of severity, our CISO and CIO escalate the matter to our Chief Operating Officer, who is another member of our Management Team, to determine next steps, as well as possible customer and external communication.
−Removed: Throughout the incident response process, the Legal team is engaged, as appropriate, and helps consider whether disclosure is required once a determination is made in connection with the company’s leadership and the CMT.
+Added: The GIS Program includes a Cyber Defense team, which manages the Incident Response Plan (Response Plan), and consists of subject matter experts from GIS and Information Governance, who work together to monitor and respond to cybersecurity incidents.
+Added: The Response Plan outlines our cyber and incident response policies and governs our incident response lifecycle, which divides overall incident response into serial phases.
+Added: The Crisis Management Team is responsible for oversight during an incident, in conjunction with the Cyber Coordination Team.
+Added: The Cyber Coordination Team manages responses to cybersecurity and compliance incidents, collaborating with subject matter experts from various departments in response to specific incidents.
+Added: When an incident reaches a certain threshold of severity, our CISO and CIO escalate the matter to our Chief Operating Officer, who is a member of our Management Team, to determine next steps, as well as possible customer and external communications.
+Added: Throughout the incident response process, the Legal team is engaged, as appropriate, and helps consider whether disclosure is required once a determination is made in connection with the company’s leadership and the Crisis Management Team.
We identify, assess and manage material risks from cybersecurity threats through our GIS Program as follows:
1 unchanged sentence
The strategy incorporates multiple layers of controls, including, monitoring, vulnerability management, identity and access management and security assessments.
−Removed: • Our program is aligned with the National Institute of Standards and Technology Cybersecurity Framework (NIST) and other technical standards and frameworks.
+Added: • Our program is aligned with the National Institute of Standards and Technology Cybersecurity Framework and other technical standards and frameworks.
• We have a robust cybersecurity defense response plan that provides a documented framework for handling security incidents and facilitates coordination across multiple parts of the company.
2 unchanged sentences
• We provide annual cybersecurity awareness and ongoing phishing training, and we routinely conduct cybersecurity attack simulation exercises, which includes participation from various levels of management.
−Removed: • Following a risk-based approach, we conduct due diligence reviews of our third party providers for potential cybersecurity risks to the company.
+Added: • Following a risk-based approach, we conduct due diligence reviews of our third-party service providers for potential cybersecurity risks to the company.
We also maintain a cross-functional Third Party Risk Management program, which partners with our GIS, Information Governance, and Operational Resilience teams, among others, to manage and monitor third party risk presented by CME Group vendors and certain third parties of third parties (fourth parties).
15 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.