12 unchanged sentences
Our Information Security program is a bespoke program created for the Company and is guided by the National Institute of Standards and Technology (NIST) Cybersecurity Framework .
−Removed: The Information Security team is composed of three core functional areas, which work collaboratively to seek to keep our assets secure:
+Added: The Information Security team is composed of three core functional areas, which work collaboratively to keep our assets secure:
• Governance, Risk, & Administration .
−Removed: Responsible for setting policy, maintaining and conducting risk assessments, ensuring regulatory compliance in partnership with our legal and compliance team, coordinating audits, evaluating new technology platforms, and the development and oversight of the Company’s data governance, vendor risk management, and training programs.
+Added: Responsible for setting policy, maintaining and conducting risk assessments, ensuring regulatory compliance in partnership with our legal and compliance team, coordinating audits, evaluating new technology platforms, and overseeing the Company’s data governance, vendor risk management, and training programs.
• Security Operations .
Responsible for monitoring our security posture on an ongoing basis, including alert response and escalation.
−Removed: This team is supported by a third-party security firm that serves as the Company’s Security Operations Center and performs continuous (24x7x365) monitoring of security across the enterprise.
+Added: This team is supported by a third-party security firm that serves as the Company’s Security Operations Center and performs continuous monitoring of security across the enterprise.
• Security Architecture .
−Removed: Responsible for managing and maintaining security systems and identity management programs, as well as oversight and performance of security reviews for key technology platforms.
+Added: Responsible for managing and maintaining security systems and identity management programs, as well as performing security reviews for key technology platforms.
The CISO leads our Information Security team and is responsible for establishing and maintaining the Enterprise Information Security Policy (the "Policy").
4 unchanged sentences
The Policy is further intended to reasonably protect our systems and data against internal and external threats that could impact it.
−Removed: We periodically review this Policy for improvements and request each account user to read and attest to the Policy annually.
+Added: We periodically review this Policy for improvements and request each account user to read and attest to the Policy as updates are made.
We employ a Defense-in-Depth approach to information security, which includes adoption of network perimeter, endpoint, and end-user controls in accordance with the Policy.
8 unchanged sentences
Incident Response Plan
−Removed: We have adopted an Incident Response Plan to provide a formal framework for responding to security incidents.
+Added: We have adopted an Incident Response Plan to provide a formal framework for responding to cybersecurity incidents.
The overall purpose of the framework is to provide procedures designed to protect and preserve the availability, integrity and confidentiality of the Company’s information and network assets, regardless of format.
12 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.