15 unchanged sentences
Cybersecurity and data protection are important for the Company to maintain the trust of our customers, team members and stakeholders.
−Removed: Overseen by the Board of Directors and its Risk Committee, we regularly review, and as appropriate, adapt our Cybersecurity Program to an evolving landscape of emerging threats, evaluate effectiveness of key security controls, and assess cybersecurity best practices.
+Added: Overseen by the Board of Directors and the Bank’s Risk Oversight Committee (the “Risk Committee”), we regularly review, and as appropriate, adapt our Cybersecurity Program to an evolving landscape of emerging threats, evaluate effectiveness of key security controls, and assess cybersecurity best practices.
The Chief Information Security Officer (“CISO”) and the Chief Technology Officer (“CTO”) are key management roles responsible for assessing and managing material risks from cybersecurity threats.
The CISO reports to the Risk Committee and is responsible for implementing and maintaining our enterprise cybersecurity organization.
−Removed: The CISO will maintain an Incident Response Plan.
−Removed: The CISO ensures that the Incident Response Plan is tested annually and will present testing results to the Risk Committee.
−Removed: The CISO and/or its delegate will share applicable threat information to ensure Board members and staff are informed on the evolving threat environment.
+Added: The CISO maintains an Incident Response Plan.
+Added: The CISO ensures that the Incident Response Plan is tested annually and presents testing results to the Risk Committee.
+Added: The CISO and/or its delegate shares applicable threat information to ensure Board members and staff are informed on the evolving threat environment.
The CISO is responsible for ensuring the Board of Directors and staff are trained annually on cybersecurity and information security awareness.
Additionally, the CISO ensures staff is adequately trained on Incident Response Plan procedures.
−Removed: The CISO will ensure security incidents are logged and maintained.
+Added: The CISO ensures security incidents are logged and maintained.
The CTO provides our Cybersecurity Program with the technical and functional resources to achieve its strategic goals and objectives, and partners and collaborates with the CISO.
1 unchanged sentence
The CISO has regular and direct communication with the Risk Committee, providing a written cybersecurity report to the Risk Committee and a written cybersecurity report and briefing to the full Board on an annual basis (more frequently as necessary), in order to inform the Risk Committee of the state of the Company’s Cybersecurity Program.
−Removed: These reports cover, but are not limited to, the Company’s cybersecurity posture, overall status of the Company’s compliance with the Cybersecurity Program, threat environment, material cybersecurity risks and events, Cybersecurity Program improvements and effectiveness, and other material matters related to the Cybersecurity Program.
+Added: These reports cover, but are not limited to, the Company’s cybersecurity posture, overall status of the Company’s compliance with the Cybersecurity Program, threat environment, material cybersecurity risks
+Added: and events, Cybersecurity Program improvements and effectiveness, and other material matters related to the Cybersecurity Program.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.