1 unchanged sentence
CYBERSECURITY
−Removed: part of the Company’s overall enterprise risk management processes, the Company maintains a cyber risk management program designed
−Removed: to identify, assess, manage, mitigate, and respond to cybersecurity threats .
−Removed: underlying processes and controls of the Company’s cyber risk management program incorporate recognized best practices and standards
−Removed: for cybersecurity and information technology, including the National Institute of Standards and Technology (“NIST”) Cybersecurity
−Removed: Framework (“CSF”).
−Removed: Elite has an annual assessment performed by a third-party specialist of the Company’s cyber risk
−Removed: management program against the NIST CSF.
−Removed: The annual risk assessment identifies, quantifies, and categorizes material cyber risks.
−Removed: addition, the Company, in conjunction with the third-party cyber risk management specialists develop a risk mitigation plan to address
−Removed: such risks, and where necessary, remediate potential vulnerabilities identified through the annual assessment process.
−Removed: addition, Elite maintains processes to help govern the processes put in place by management designed to protect the Company’s IT
−Removed: assets, data, and services from threats and vulnerabilities.
−Removed: Elite employs additional key practices within the cybersecurity risk management
−Removed: program including, but not limited to maintenance of an IT assets inventory, identity access management controls including restricted
−Removed: access of privileged accounts, physical security measures at Company facilities, information protection (IPS)/detection systems (IDS)
−Removed: including maintenance of firewalls, network and data traffic monitoring and automated alerting, and critical data backups to reduce cybersecurity
−Removed: The Company’s cybersecurity
−Removed: partners, including, consultants, and other third-party service providers are a key part of Elite Pharmaceutical’s
−Removed: cybersecurity risk management strategy and infrastructure.
−Removed: Elite partners with industry recognized cybersecurity providers leveraging
−Removed: third-party technology and expertise and engages with these partners to monitor and maintain the performance and effectiveness of IT
−Removed: assets, data, and services that are deployed in the Company’s environment.
−Removed: The cybersecurity partners provide services including,
−Removed: but not limited to systems inventory monitoring, user management, network protection and monitoring, IPS/IDS management, remote access
−Removed: monitoring and management, user activity monitoring, data backups management, cybersecurity strategy, and cyber risk advisory, including
−Removed: assessment and remediation.
−Removed: management team, in conjunction with cybersecurity service providers, is responsible for oversight and administration of Elite’s
+Added: Management & Strategy
+Added: maintains a cyber risk management program designed to identify, assess, manage, mitigate and respond to cybersecurity threats.
+Added: addresses cybersecurity risks to corporate information technology, or IT, environment including systems, hardware, software, data, people
+Added: and processes.
+Added: underlying processes and controls of Elite’s cyber risk management program incorporate recognized best practices and standards
+Added: for cybersecurity and information technology, including principles of the National Institute of Standards and Technology (“NIST”)
+Added: Cybersecurity Framework 2.0 (“CSF”), and processes and controls supporting data protection requirements under applicable
+Added: NIST CSF offers a thorough set of guidelines and best practices to help establish a strong cybersecurity posture.
+Added: Aligning our cybersecurity
+Added: processes and controls to NIST CSF enables us to systemically identify, assess, and manage cybersecurity risks most relevant and impactful
+Added: to our business operations.
+Added: It is important to note that using the NIST CSF as a guide does not imply our cybersecurity program meets
+Added: any specific technical standards or requirements.
+Added: engages a third-party specialist to perform an annual assessment of its cybersecurity risk management program against the NIST CSF.
+Added: annual risk assessment identifies, quantifies, and categorizes material cyber risks.
+Added: Elite, in conjunction with its third-party cyber
+Added: risk management specialists, develops a risk mitigation plan to address such risks, and where necessary, remediate potential vulnerabilities
+Added: identified through the annual assessment process.
+Added: In evaluating the risks identified through the annual cybersecurity risk assessment process,
+Added: our cybersecurity specialists and partners, including but not limited to Managed Service Providers, assist Elite to assess and prioritize
+Added: the likelihood, severity, and impact of relevant risks, including the impact on employees, stakeholders, and vendors.
+Added: addition, Elite maintains governance processes and controls designed to protect Elite’s IT assets, data, and services from threats
+Added: and vulnerabilities.
+Added: Elite employs key practices within the cybersecurity risk management program including maintaining restricted access
+Added: to privileged accounts, intrusion prevention systems/detection systems including maintenance of protection systems such as firewalls,
+Added: network and data traffic monitoring, and critical data backups to mitigate cybersecurity risk.
+Added: cybersecurity partners, including consultants and other third-party service providers, are a key part of Elite’s cybersecurity
+Added: risk management strategy and infrastructure.
+Added: Elite partners with industry-recognized cybersecurity providers leveraging third-party technology
+Added: and expertise and engages with these partners to monitor and maintain the performance and effectiveness of IT assets, data, and services
+Added: that are deployed in company data and technology environment.
+Added: The cybersecurity partners provide services necessary to maintain Elite’s
+Added: IT infrastructure and execute the current cybersecurity strategy, including continuous improvement and remediation efforts.
+Added: monitors service level agreements and third-party contracts as part of our efforts to monitor third-party risks associated with reliance on vendors, critical service
+Added: providers, and other third-parties that may lead to service disruption or an adverse cybersecurity incident.
+Added: cybersecurity risk management program includes an incident response plan that includes relevant and critical members of management and
+Added: third-party service providers alike.
+Added: This team is responsible for assessing and managing cybersecurity incident response processes, response
+Added: times, and communication plans in the event corrective actions and mitigation procedures are required to isolate and eradicate an incident.
+Added: management team, with assistance from cybersecurity service providers, is responsible for oversight and administration of Elite’s
cyber risk management program, and for informing senior management and other relevant stakeholders regarding the prevention, detection,
mitigation, and remediation of cybersecurity incidents.
−Removed: The Company’s management team has prior experience selecting, deploying,
−Removed: and overseeing cybersecurity technologies, initiatives, and processes directly or via selection of strategic third-party partners, and
−Removed: also relies on threat intelligence as well as other information obtained from governmental, public or private sources, including external
−Removed: consultants engaged by Elite for strategic cyber risk management, advisory and decision making.
+Added: Elite’s management team has prior experience selecting, deploying, and
+Added: overseeing cybersecurity technologies, initiatives, and processes directly or via the use of strategic third-party partners.
+Added: management team also relies on threat intelligence as well as other information obtained from governmental, public or private sources,
+Added: including external consultants engaged by Elite for strategic cyber risk management, advisory and decision making.
Audit Committee of the Board of Directors oversees Elite’s cybersecurity risk exposures and the steps taken by management to monitor
5 unchanged sentences
This includes updates on processes to prevent, detect, and mitigate cybersecurity incidents.
−Removed: The Company also relies on threat intelligence and other information obtained from governmental, public, or private sources, including
−Removed: external consultants engaged by the Company for strategic cyber risk management, advisory and decision making.
−Removed: has implemented third-party risk management processes to manage the risks associated with reliance on vendors, critical service providers,
−Removed: and other third-parties that may lead to a service disruption or an adverse cybersecurity incident.
−Removed: This includes service level agreement
−Removed: monitoring and contract negotiations.
−Removed: faces risks from cybersecurity threats that could have a material
−Removed: effect on its business, financial condition, results of operations, cash flows or reputation.
−Removed: Elite acknowledges that the risk of cyber
−Removed: incident is prevalent in the current threat landscape and that a future cyber incident may occur in the normal course of its business .
−Removed: However, as of the date of this Annual Report on Form 10-K, the Company is not aware of any risks from cybersecurity threats that have
−Removed: materially affected or are reasonably likely to materially affect Elite’s business strategy, financial condition, results of operations,
−Removed: or cash flows.
−Removed: The Company proactively seeks to detect and investigate unauthorized attempts and attacks against Company IT assets, data,
−Removed: and services, and to prevent their occurrence and recurrence where practicable through changes or updates to internal processes and tools
−Removed: and changes or updates to Company service delivery;
−Removed: however, potential vulnerabilities to known or unknown threats will still remain.
−Removed: Further, there is increasing regulation regarding responses to cybersecurity incidents, including reporting to regulators, investors,
−Removed: and additional stakeholders, which could subject the Company to additional liability and reputational harm.
−Removed: In response to such risks,
−Removed: the Company has implemented initiatives such as implementation of the cybersecurity risk assessment process and development of an incident
−Removed: response plan.
−Removed: “ Risk Factors ” for more information on cybersecurity risks.
+Added: faces risks from cybersecurity threats that could have a material adverse effect on its business, financial condition, results of operations,
+Added: cash flows or reputation.
+Added: Elite acknowledges that the risk of cyber incidents is prevalent in the current threat landscape and that a
+Added: future cyber incident may occur in the normal course of its business.
+Added: However, as of the date of this Annual Report on Form 10-K, Elite
+Added: is not aware of any risks from cybersecurity threats that have materially affected or are reasonably likely to materially affect Elite’s
+Added: business strategy, financial condition, results of operations, or cash flows.
+Added: Elite proactively seeks to detect and investigate unauthorized
+Added: attempts and attacks against IT assets, data, and services, and to prevent their occurrence and recurrence where practicable through
+Added: changes or updates to internal processes and tools and changes or updates to Elite’s service delivery;
+Added: however, potential vulnerabilities
+Added: to known or unknown threats will still remain.
+Added: Further, there are continuous regulatory considerations regarding responses to cybersecurity
+Added: incidents, including reporting to regulators, investors, and additional stakeholders, which could subject Elite to additional liability
+Added: and reputational harm.
+Added: In response to such risks, Elite has implemented initiatives such as implementation of the cybersecurity risk
+Added: assessment process and development of an incident response plan.
+Added: “ Risk Factors ” for more information
+Added: on cybersecurity risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.