8 unchanged sentences
In general, the Company addresses cybersecurity risks through a comprehensive, cross-functional approach that is focused on confidentiality, security and availability of the information that the Company collects and stores by identifying, preventing, and mitigating cybersecurity threats and effectively responding to cyber threats when they occur.
−Removed: As one of the elements of the Company’s overall enterprise-wide risk management approach, the Information Security Program is focused on the following key areas:
+Added: As one of the elements of the Company’s overall enterprise-wide risk management approach, our Information Security Program is focused on the following key areas:
• Security Operation and Governance:
9 unchanged sentences
• Third-Party Risk Management:
−Removed: Management of the Company’s third parties, including vendors and service providers, is conducted through a risk-based approach and the level of due diligence is driven from risk factors established by our Risk Management department.
−Removed: The process provides awareness and collaboration across internal teams including Information Security and Business Continuity.
−Removed: A Technical Requirements review process is conducted on new or significantly changed third parties, applications, or technology to ensure that systems or third parties meet certain security baseline requirements.
−Removed: This process is aimed at advocating the necessary security, infrastructure, and application standards or controls so that information systems and the third party have recovery plans in place.
+Added: Management of the Company’s third parties, including vendors and service providers, is conducted through a risk-based approach and the level of due diligence is driven from risk factors established by our Risk Management program.
+Added: The process provides awareness and collaboration
+Added: across internal teams including, but not limited to, Information Technology, Information Security and Business Continuity.
+Added: In addition to ongoing monitoring of select vendors, a review is conducted on new or significantly changed third parties, applications, and technology to ensure that systems and third parties meet certain baseline requirements.
+Added: This process is used to identify and monitor risks in vendor arrangements and assists management in establishing appropriate risk responses.
• Security Awareness and Education:
−Removed: The Company provides annual, mandatory training for personnel regarding security awareness as a means to equip the Company’s personnel with the understanding of how
−Removed: to properly use and protect the computing resources entrusted to them, and to communicate the Company’s information security policies, standards, processes and practices.
+Added: The Company provides annual, mandatory training for personnel regarding security awareness as a means to equip the Company’s personnel with the understanding of how to properly use and protect the computing resources entrusted to them, and to communicate the Company’s information security policies, standards, processes and practices.
The Company leverages regular assessments to identify current and potential threats and vulnerabilities within the Company’s environment.
6 unchanged sentences
The Risk Committee of the Board provides direction and oversight of the enterprise-wide risk management framework of the Company, including the management of risks arising from cybersecurity threats.
−Removed: The Board Risk Committee reviews and approves the Information Security Program and receives regular presentations which include updates on cybersecurity risks, including the threat environment, evolving standards, projects and initiatives, vulnerability assessments, third-party and independent reviews, technological trends and information security considerations arising with respect to the Company’s peers and third parties.
−Removed: The Board Risk Committee also receives information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
−Removed: The full Board receives reports from the Board Risk Committee related to information cybersecurity.
−Removed: Our Chief Information Officer ("CIO"), works collaboratively across the Company to implement a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with the Company’s Incident Response Plans including an assessment of the potential materiality of any cybersecurity incident.
+Added: The Risk Committee receives periodic presentations which include updates on cybersecurity risks, including the threat environment, evolving standards, projects and initiatives, vulnerability assessments, third-party and independent reviews, technological trends and information security considerations arising with respect to the Company’s peers and third parties.
+Added: The Risk Committee also receives information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding any such incident until it has been addressed.
+Added: The full Board receives reports from the Risk Committee related to information cybersecurity.
+Added: Our Chief Operating Officer ("COO") , works collaboratively across the Company to implement a program designed to protect the Company’s information systems from cybersecurity threats and to promptly respond to any cybersecurity incidents in accordance with the Company’s Incident Response Plans, including an assessment of the potential materiality of any cybersecurity incident.
To facilitate the success of the Company’s cybersecurity risk management program, multidisciplinary teams throughout the Company are deployed to address cybersecurity threats and to respond to cybersecurity incidents.
−Removed: Through ongoing communications with these teams, the CIO, Information Security, and Risk Management teams monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Corporate Crisis Management Team and ultimately the Board when appropriate.
+Added: Through ongoing communications with these teams, the COO, Information Security, and Risk Management teams monitor the prevention, detection, mitigation and remediation of cybersecurity threats and incidents in real time, and report such threats and incidents to the Corporate Crisis Management Team and ultimately the Board when appropriate.
+Added: We believe our Board and management, including the Chief Operating Officer, have the appropriate expertise, background, and depth of experience to manage risks arising from cybersecurity threats, including applicable knowledge gained through industry experience, internal and external training, and periodic discussions with consultants and peers with applicable knowledge and expertise.
+Added: In addition, members of our management hold varying levels of relevant cybersecurity certifications.
To our knowledge, neither cybersecurity threats, nor the results including as a result of any previous cybersecurity incidents have materially affected the Company, including its business strategy, results of operations or financial condition.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.