ITEM 1B — UNRESOLVED STAFF COMMENTS
+Added: Table of Conte nts
ITEM 1C — CYBERSECURITY
10 unchanged sentences
The CSIRT provides threat intelligence information to our CSO, broader security and resiliency organization, and relevant business units and functional areas.
−Removed: We also engage third parties in connection with our cybersecurity risk management processes, including cybersecurity consultants and auditors, to conduct evaluations of our security controls and provide certifications for industry-standard security frameworks, such as ISO27001 and PCI-DSS.
−Removed: In addition to monitoring risks from threats to our own assets, we administer a third-party risk management program that endeavors to help identify and manage risks from cybersecurity threats arising from our suppliers and other service provider organizations.
+Added: We also engage third parties in connection with our cybersecurity risk management processes, including cybersecurity consultants and auditors, to conduct evaluations of our security controls and provide certifications for industry-standard security frameworks, such as ISO27001 and SOC, Type 2.
+Added: In addition to monitoring risks from threats to our own assets, we administer a third-party risk management program that helps identify and manage risks from cybersecurity threats arising from attacks against our suppliers and other service provider organizations.
This program seeks to combine a methodology for risk ratings with targeted cybersecurity assessments, security-focused contractual requirements, and monitoring activities based on the risk profile of covered suppliers and service providers.
−Removed: Our CSO reports to our General Counsel and has principal executive responsibility and oversight for the Company’s strategy, planning, and operations on the management of both physical and cybersecurity risk.
+Added: Our CSO reports to our General Counsel and has principal executive responsibility and oversight for the Company’s strategy, planning, and operations on the management of both physical security and cybersecurity risk.
Our CSO has extensive cybersecurity and program management experience and previously served in relevant leadership positions at another large multinational corporation and the U.S.
Department of Defense.
−Removed: He is supported by our Chief Information Security Officer, who has extensive cybersecurity experience in both the private and public sectors, and a team of cybersecurity professionals with relevant and expansive educational and industry experience.
+Added: He is supported by our CISO, who has extensive cybersecurity experience in both the private and public sectors, and a team of cybersecurity professionals with relevant and expansive educational and industry experience.
Cybersecurity risk management has been integrated into the Company’s overall enterprise risk management program (“ERM”) through the Company’s enterprise risk governing bodies, which are the Global Risk and Compliance Council (“GRCC”) and the Enterprise Risk Steering Committee (“ERSC”).
4 unchanged sentences
The Board of Directors meets with our CSO or his delegate annually to review significant cybersecurity risks as well as cybersecurity priorities and focus areas for the upcoming fiscal year.
−Removed: The Audit Committee meets with our CSO or his delegate quarterly to review significant cybersecurity incidents and risks, as well as progress made towards key cybersecurity initiatives and matters.
+Added: The Audit Committee meets with our CSO or his delegate quarterly to review significant cybersecurity incidents and risks, programmatic security modifications and enhancements, and progress made towards key cybersecurity initiatives and matters.
The CSO may provide more frequent updates to the Board of Directors and Audit Committee if necessitated by a security incident or other developments.
The Audit Committee reports regularly to our Board of Directors regarding the committee’s oversight of cybersecurity risk matters.
+Added: Table of Conte nts
To date, no risks from cybersecurity threats, including as a result of any previous cybersecurity incident, have materially affected our business strategy, results of operations, or financial condition.
1 unchanged sentence
For a discussion of cybersecurity risks affecting our business, see “Item 1A—Risk Factors—Risks Relating to Our Business and Our Industry.” Although we maintain cybersecurity insurance, the costs related to cybersecurity incidents may not be fully insured.
+Added: Table of Conte nts
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.