6 unchanged sentences
We have implemented a cybersecurity program including processes, technologies, and controls to assess, identify, and manage material risks from cybersecurity threats .
−Removed: This program includes implementing new technologies to proactively identify and monitor new vulnerabilities and reduce risk, conducting due diligence of third-party vendors’ information security programs, maintaining security policies and standards and regularly updating and testing our response planning and protocols.
−Removed: We maintain a formal information security training program for employees that includes training on matters such as phishing and email security best practices.
+Added: This program includes implementing and evolving new technologies to proactively identify and monitor new vulnerabilities and reduce risk, conducting due diligence of third-party vendors’ information security programs, maintaining security policies and standards and regularly updating and testing our response planning and protocols.
+Added: We maintain a formal information security training program for employees that includes training on matters such as identifying phishing attempts and web browsing/email security best practices.
Employees are also required to complete mandatory training on data privacy.
We also have a third-party cybersecurity risk review process, including requiring key third-party service providers to complete initial and periodic security assessments, which prioritizes, monitors and assesses the risks associated with our third-party service provider interactions.
−Removed: To evaluate and enhance our cybersecurity program, we periodically utilize third-party experts to undertake maturity assessments of the program.
+Added: To evaluate and enhance our cybersecurity program, we periodically utilize third-party experts to undertake maturity assessments and security testing of the program.
We have also adopted a cybersecurity incident response plan that is designed to effectively identify, analyze, contain, remediate and eradicate, escalate, report, and appropriately document cybersecurity incidents.
8 unchanged sentences
The Audit Committee of the Board of Directors oversees our information security program, which includes oversight of the cybersecurity program and management of cybersecurity risks.
−Removed: The Audit Committee receives at least semi-annual updates from the CISO, which typically address our cybersecurity strategy, initiatives, key security metrics, business response plans and the evolving cyber threat landscape and a detailed threat assessment relating to information technology risks.
+Added: The Audit Committee receives periodic updates from the CISO, which typically address our cybersecurity strategy, initiatives, key security metrics, business response plans and the evolving cyber threat landscape and a detailed threat assessment relating to information technology risks.
At the management level, our cybersecurity program is led by the CISO, who is responsible for assessing and managing material risks from cybersecurity threats, including the prevention, mitigation, detection, and remediation of cybersecurity incidents.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.