17 unchanged sentences
Risk Assessment
−Removed: At least annually, we conduct a cybersecurity risk assessment using the FFIEC Cybersecurity Assessment Tool that considers information from internal stakeholders, known information security vulnerabilities, and information from external sources (e.g., reported security incidents that have impacted other companies, industry trends, and evaluations by third parties and consultants).
−Removed: The results of the assessment are used to drive alignment on, and prioritization of, initiatives to enhance our security controls, make recommendations to improve processes, and inform a broader enterprise-level risk assessment that is presented to our Board, Audit Committee, and members of management.
+Added: At least annually, we conduct a cybersecurity risk assessment using the Cyber Risk Institute Cyber Profile which is based on the NIST “Framework for Improving Critical Infrastructure Cybersecurity.” The results of the assessment are used to drive alignment on, and prioritization of, initiatives to enhance our security controls, make recommendations to improve processes, and inform a broader enterprise-level risk assessment that is presented to our Board, Audit Committee, and members of management.
Technical Safeguards
24 unchanged sentences
Our Board of Directors has ultimate oversight of cybersecurity risk, which it manages as part of our enterprise risk management program.
−Removed: The Board receives regular reports from our Vice President Director of Information Security on various cybersecurity efforts, including risk assessments, mitigation strategies, areas of emerging risks, incidents and industry trends, and other areas of importance.
+Added: The Board receives regular reports from our Vice President Chief Information Security Officer on various cybersecurity efforts, including risk assessments, mitigation strategies, areas of emerging risks, incidents and industry trends, and other areas of importance.
In addition, we have an escalation process in place to inform senior management and the Board of Directors of material issues.
Management ’ s Role
−Removed: Our cybersecurity program is coordinated by our Vice President Director of Information Security, who reports to our Senior Vice President Chief Risk Officer and Chief Administrative Officer, in partnership with our Director of Information Systems and Technology ("IS&T").
−Removed: Our Director of Information Security started with us in 2012 and holds numerous credentials including:
+Added: Our cybersecurity program is coordinated by our Vice President Chief Information Security Officer, who reports to our Senior Vice President Chief Risk Officer and Chief Administrative Officer, in partnership with our Vice President Chief Information Officer.
+Added: Our Chief Information Security Officer started with us in 2012 and holds numerous credentials including:
Certified Information Systems Security Professional, Certified Public Accountant, and Certified Fraud Examiner.
−Removed: The Director of Information Security is informed about and monitors prevention, detection, mitigation, and remediation efforts through regular communication and reporting from the IS&T team and our Managed Services Provider, who is overseen by the Director of IS&T.
−Removed: The Director of IS&T started with us in 2020, holds a Bachelor of Science in Business Administration, Information Technology and has over 15 years of direct experience managing information systems and technology.
−Removed: The Director of IS&T is responsible for implementing and maintaining the systems and tools to protect the technology stack we use.
−Removed: The Director of IS&T reports to the Senior Vice President, Chief Operating Officer.
+Added: The Chief Information Security Officer is informed about and monitors prevention, detection, mitigation, and remediation efforts through regular communication and reporting from the IS&T team and our Managed Services Provider, who is overseen by the Chief Information Officer.
+Added: The Chief Information Officer started with us in 2020, holds a Bachelor of Science in Business Administration, Information Technology and has over 15 years of direct experience managing information systems and technology.
+Added: The Chief Information Officer is responsible for implementing and maintaining the systems and tools to protect the technology stack we use.
+Added: The Chief Information Officers reports to the Executive Vice President, Chief Operating Officer.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.