24 unchanged sentences
Management Oversight and Governance
−Removed: The Company’s Chief Information Security Officer (“CISO”), who reports to the Executive Vice President, Software, is responsible for the design and implementation of our security program and strategy based on the mandate provided by the Board and senior management.
+Added: The Company’s Chief Information Security Officer (“CISO”), who reports to the President, Software, is responsible for the design and implementation of our security program and strategy based on the mandate provided by the Board and senior management.
The CISO has extensive experience in the management of cybersecurity risk management programs, having served in various leadership roles in information technology and information security for over 20 years, including serving as the Chief Security Officer of two other large public technology companies.
3 unchanged sentences
Through ongoing communications with these teams, the CISO and senior management are informed promptly about, and monitor the prevention, detection, investigation, mitigation and remediation of, cybersecurity threats.
−Removed: These teams are expected to operate pursuant to documented plans and playbooks that include processes for escalation of incidents to leadership and to the Audit Committee and Board, as appropriate, based on the severity level of an incident.
+Added: These teams are expected to operate pursuant to documented plans and playbooks that include processes for escalation of incidents to leadership and to the Audit Committee and the Board, as appropriate, based on the severity level of an incident.
In addition, the Company periodically consults with outside advisors and experts to assist with assessing, identifying and managing cybersecurity risks, including to anticipate future threats and trends, and their impact on the Company’s risk management environment.
19 unchanged sentences
Our management is responsible for identifying the various risks facing the Company, formulating risk management policies and procedures, and managing the Company’s risk exposures.
−Removed: Our Board of Directors’ responsibility is to monitor the Company’s risk management processes by informing itself concerning our material risks and evaluating whether management has reasonable controls in place to address the material risks.
−Removed: The Audit Committee of the Board of Directors is responsible for discussing with management the Company’s major risk exposures and the steps management has taken to monitor and control such exposures, including the Company’s risk assessment and risk management policies.
+Added: Our Board responsibility is to monitor the Company’s risk management processes by informing itself concerning our material risks and evaluating whether management has reasonable controls in place to address the material risks.
+Added: The Audit Committee of the Board is responsible for discussing with management the Company’s major risk exposures and the steps management has taken to monitor and control such exposures, including the Company’s risk assessment and risk management policies.
Accordingly, our internal risk management team regularly reports to the Audit Committee on our major risk exposures and the steps management has taken to monitor and control such exposures, including our risk assessment and risk management policies.
−Removed: The Audit Committee, in turn, reports on the matters discussed at the committee level to the full Board of Directors.
+Added: The Audit Committee, in turn, reports on the matters discussed at the committee level to the full Board .
As part of its oversight of the Company’s risk management noted above, the Audit Committee oversees, reviews and discusses with management the Company’s risks from cybersecurity threats and management’s role in assessing and managing such risks.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.