UNRESOLVED STAFF COMMENTS.
−Removed: Table of Con ten ts
CYBERSECURITY.
5 unchanged sentences
The Company stores data on premise and in cloud environments, with security appropriate to the data involved and has adopted controls around, among other things, access and acceptable use, backup and recovery and vendor risk assessment.
−Removed: Our cybersecurity program is managed by the Cyber Incident Response Team (the “CIRT”), which is led by the Global IT Director, System Infrastructure Manager and the Network Infrastructure Manager, each with over 20 years of experience in IT.
+Added: We also have processes in place designed to mitigate risks from third-party technology and service providers, including, as appropriate, pre-contractual due diligence, review of contractual terms addressing cybersecurity and data protection, and periodic reassessment based on assessed vendor risk.
+Added: Our cybersecurity program is managed by the Cyber Incident Response Team (the “CIRT”), which is led by the Senior IT Director, Cybersecurity Manager, and the Infrastructure Operations Manager , each with over 20 years of experience in information technology.
The CIRT serves as the core team responsible for managing the enterprise-wide cybersecurity policy, maintenance and compliance across all platforms.
3 unchanged sentences
In the event of a potential cybersecurity incident, the CIRT will conduct an assessment to determine the nature and scope of the incident and manages the incident in accordance with our incident response plan until the incident is contained and resolved.
−Removed: The CIRT will document findings and make them available to the Disclosure Committee, which includes cross functional senior management representation from information technology, legal, finance, investor relations and business segments.
+Added: The CIRT will document findings and make them available to the Disclosure Committee, which includes cross functional senior management representation from information technology, legal, finance, investor relations and the business.
The Disclosure Committee, in conjunction with third-party experts, including outside legal counsel, is responsible for assessing the materiality of any cybersecurity incident and coordinating external communications and disclosures, including with the Securities and Exchange Commission.
10 unchanged sentences
The Board has delegated to the Audit Committee the responsibility to oversee the integrity of the Company’s information technology and cybersecurity risks and to assess the risks and incidents relating to cybersecurity threats.
−Removed: While our Board and Audit Committee oversee cybersecurity risk, management, through the CIRT, is responsible for the implementation and management of cybersecurity risk
−Removed: Table of Con ten ts
−Removed: management systems and processes and for the communication of incidents to senior management and the Audit Committee.
−Removed: The CIRT meets with the CEO and other members of our senior management on a quarterly basis and meets with the Audit Committee at least annually.
+Added: While our Board and Audit Committee oversee cybersecurity risk, management, through the CIRT, is responsible for the implementation and management of cybersecurity risk management systems and processes and for the communication of incidents to senior management and the Audit Committee.
+Added: The CIRT meets with the Chief Executive Officer and other members of our senior management on a quarterly basis and meets with the Audit Committee at least annually.
Additionally, the Audit Committee regularly meets with members of the Company’s internal audit function to discuss risk management activities, compliance, best practices, and other related matters.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.