6 unchanged sentences
Our information security management system (ISMS) program is aligned to ISO 27001, which is an international standard to manage information security.
−Removed: ISO 27001 is published by the International Organization for Standardization (ISO), the world's largest developer of voluntary standards, and the International Electrotechnical Commission (IEC).
−Removed: Our information technology (IT) security department, led by our Senior Vice President (SVP) IT Infrastructure & Security, is tasked with monitoring cybersecurity and operational risks related to information security and system disruption.
−Removed: The team employs measures designed to protect against, detect, and respond to cybersecurity threats, and has implemented processes and procedures aligned with our information security management system to support and promote resilient programs.
+Added: ISO 27001 is published by the International Organization for Standardization (ISO), the world's largest developer of voluntary standards, and the International Electrotechnical Commission.
+Added: Our IT security department, led by our Senior Vice President (SVP) IT Infrastructure & Security, is tasked with monitoring cybersecurity and operational risks related to information security and system disruption.
+Added: The team employs measures designed to protect against, detect, and respond to cybersecurity threats, and has implemented processes and procedures aligned with our ISMS to support and promote resilient programs.
This includes:
−Removed: • Enterprise security framework and cyber security standards;
−Removed: • Cyber security awareness and training plans;
+Added: • Enterprise security framework and cybersecurity standards;
+Added: • Cybersecurity awareness and training plans;
• Security assessments and monitoring;
13 unchanged sentences
Any issues identified during assessment are tracked through to remediation.
−Removed: Our Board of Directors and Audit Committee are actively engaged in the oversight of our risk management, including cybersecurity risk.
+Added: Our Board and Audit Committee are actively engaged in the oversight of our risk management, including cybersecurity risk.
The Audit Committee receives quarterly reports on information security from our SVP IT Infrastructure & Security.
2 unchanged sentences
Our IT security department, which assesses and manages our risks from cybersecurity threats, is led by our SVP IT Infrastructure & Security, who reports to our Senior EVP IT.
−Removed: Additional oversight for assessing and managing cybersecurity risk include Executive sponsors, Information Technology, Human Resources, IT Governance Risk and Compliance, Internal Audit, and Legal, as well as members of our Information Security Risk Council, IT Risk Committee, and Enterprise Risk Management teams.
+Added: Additional oversight for assessing and managing cybersecurity risk include Executive sponsors, IT, Human Resources, IT Governance Risk and Compliance, Internal Audit, and Legal, as well as members of our Information Security Risk Council, IT Risk Committee, and ERM teams.
We have in place an incident response plan to identify, protect, detect, respond to, and recover from cybersecurity threats and incidents.
6 unchanged sentences
There have been no previous cybersecurity incidents which have materially affected us to date, including our business strategy, results of operations or financial condition.
−Removed: However, any future potential risks from cybersecurity threats, including but not limited to exploitation of vulnerabilities, ransomware, denial of service, supply chain attacks, or other similar threats may materially affect us, including our execution of business strategy, reputation, results of operations and/or financial condition.
+Added: However, any future potential risks from cybersecurity threats, including but not limited to exploitation of vulnerabilities, ransomware, denial of service, supply chain attacks, and the use of artificial intelligence by threat actors engaged in these activities, or other similar threats may materially affect us, including our execution of business strategy, reputation, results of operations and/or financial condition.
+Added: For additional information regarding cybersecurity threats, see 'Item 1A.
+Added: Risk Factors' of this Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.