8 unchanged sentences
The Board is responsible for the oversight of cybersecurity risk management, as well as the selection of a Chief Information Security Officer (“CISO”), the management official responsible for administering and executing the information security program.
−Removed: The Board’s Technology Oversight Committee (“TOC”) assists the Board in its oversight of the information security program.
−Removed: The TOC reviews information security metrics, oversees significant instances of non-compliance with the
−Removed: information security policy and monitors remediation of those instances, and reviews the appointment of the CISO for recommendation to the Board.
−Removed: At the management level, the Enterprise Risk Management Committee (“ERMC”) is primarily responsible for cybersecurity risk management.
+Added: The Board’s Technology Oversight Committee (the “TOC”) assists the Board in its oversight of the information security program.
+Added: The TOC reviews information security metrics, oversees significant instances of non-compliance with the information security policy and monitors remediation of those instances, and reviews the appointment of the CISO for recommendation to the Board.
+Added: At the management level, the Enterprise Risk Management Committee (the “ERMC”) is primarily responsible for cybersecurity risk management.
As it pertains to the information security program, the ERMC assesses and monitors information security risks and approves the information security policy on at least an annual basis.
2 unchanged sentences
Our CISO is responsible for the overall administration and execution of the information security program and reports to our Chief Risk Officer (“CRO”).
−Removed: Our CISO has over thirty years of experience working in information security for a variety of companies and organizations, including multiple financial institutions.
+Added: Our CISO has over fifteen years of experience working in information security and risk for a variety of companies and organizations, including multiple financial institutions .
The CISO monitors the security of, among other things, systems, applications, tools, databases, computers, websites, cloud infrastructure, vendor tools, and user access systems.
4 unchanged sentences
The CISO coordinates the Company’s response to a cybersecurity incident, including investigating, recording and evaluating any potential, suspected or confirmed incidents involving non-public customer information or Company confidential information.
−Removed: On a regular basis, the CISO reports to the CRO information security risk issues, risk mitigation progress and developments, and information security enhancement initiatives.
−Removed: The CISO also reports the status of information security-related key risk indicators to the CRO.
−Removed: The CISO reports to the TOC monthly on information security developments and emerging risks, both in the industry and specific to the Company.
−Removed: The CISO and CRO report on the information security program to the TOC and the ERMC and review and propose updates to the information security policy to the ERMC.
+Added: On a regular basis, the CISO discusses with the CRO information security risk issues, risk mitigation progress and developments and information security enhancement initiatives.
+Added: The CISO reports to the TOC quarterly on information security developments and emerging risks, both in the industry and specific to the Company.
+Added: The CISO and CRO report on the information security program, including the status of information security-related key risk indicators, to the TOC and the ERMC.
+Added: The Information Security Policy is also approved by the TOC on an annual basis.
+Added: Table o f Contents
The Company employs third parties in certain aspects of its information security and cybersecurity risk management.
−Removed: For example, we engage third parties to assess the information security risks related to new products, and we utilize third parties to conduct certain security operations and maintain certain information security infrastructure.
−Removed: We have adopted a Contract and Vendor Management Policy, which addresses the identification, measurement, monitoring, and management of our third-party service provider relationships, including those related to information security.
−Removed: The CISO assesses and monitors information risks posed by third parties and any non-compliance with the controls created to address such risks.
−Removed: With respect to cybersecurity incidents affecting our third party service providers, the CISO works with our service providers to understand and document any incidents, along with managing the impact to us and reporting such incidents to the CRO, ERMC, TOC, and, if applicable, the Board.
+Added: For example, we utilize third parties to conduct certain security operations and maintain certain information security infrastructure.
+Added: We have adopted a Third Party Risk Management Policy, which addresses the identification, measurement, monitoring, and management of our third-party service provider relationships, including those related to information security.
+Added: The Director of Third-Party Risk Management, along with the CISO, assess and monitor information risks posed by third parties and any non-compliance with the controls created to address such risks.
+Added: With respect to cybersecurity incidents affecting our third-party service providers, the Director of Third-Party Risk Management works with our service providers to understand and document any incidents, along with managing the impact to us and reporting such incidents to the CRO, ERMC, TOC, and, if applicable, the Board.
To date, we have not incurred any material losses related to cybersecurity incidents.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.