10 unchanged sentences
The Incident Response Team will document findings and make them available to the Incident Classification Team, which is comprised of our CISO, Executive Vice President of Production Engineering, Chief Information Officer, Chief Legal & Compliance Officer, or CLO, Chief Operating Officer, Chief Financial Officer, and their respective delegates.
−Removed: The Incident Classification Team is responsible for assessing the incident and
−Removed: notifying members of our management and our Board.
−Removed: Our Chief Executive Officer, CLO and CISO, in conjunction with third party experts, including outside legal counsel and our internal disclosure committee, are responsible for coordinating external communications and disclosures, including with the Securities and Exchange Commission.
+Added: The Incident Classification Team is responsible for assessing the incident and notifying members of our management and our Board.
+Added: Our Chief Executive Officer, CLO, CISO and CFO, in conjunction with third-party experts , including outside legal counsel and our internal disclosure committee, are responsible for coordinating external communications and disclosures, including with the Securities and Exchange Commission.
Our ISMS has a risk based formulation.
9 unchanged sentences
• cybersecurity awareness training of our employees, incident response personnel, and senior management, which covers a variety of topics designed to educate our employees about the importance of cybersecurity awareness, highlight typical cybersecurity-related risks and issues, such as phishing attacks and other methods used to attempt to infiltrate our systems, and test that awareness using knowledge assessments and simulations;
−Removed: • external cybersecurity consultants, including Palo Alto Networks Unit 42 Incident Response team, supervised by our Incident Response Team and Incident Classification Team;
+Added: • external cybersecurity consultants, supervised by our Incident Response Team and Incident Classification Team;
• a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents;
• a third-party risk management process for service providers, suppliers, and vendors, pursuant to which we require such third parties to maintain certain security controls and assess their compliance with these requirements;
−Removed: • independent third party assessments and audits of our ISMS to determine if it meets the requirements of international information security standards such as ISO 27001:2013, PCI DSS 3.2.1, HIPAA HiTech, AICPA SOC criteria for Security and Availability requirements.
+Added: • independent third-party assessments and audits of our Information Security Management System, or ISMS, to monitor compliance with globally recognized information security standards, including ISO 27001:2013/2022, ISO 27017:2015 (cloud security best practices), PCI DSS 4.0, HIPAA HiTech, and the AICPA SOC 2 criteria for Security and Availability.
We have not identified risks from known cybersecurity incidents, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
2 unchanged sentences
Julie Iskow, Ms.
−Removed: Sue Barsamian, Mr.
−Removed: David Welsh and Mr.
−Removed: David DeWalt.
+Added: Sue Barsamian and Mr.
Our Board receives quarterly reports from management on our cybersecurity processes and risks.
3 unchanged sentences
Our management, including our CISO , oversees cybersecurity threats using our Incident Response Team and Incident Classification Team.
−Removed: Our management is responsible for assessing and managing our material risks from cybersecurity threats and incidents and has the primary responsibility for our overall cybersecurity risk management
−Removed: program and supervise both our internal cybersecurity personnel and our retained external cybersecurity consultants.
+Added: Our management is responsible for assessing and managing our material risks from cybersecurity threats and incidents and has the primary responsibility for our overall cybersecurity risk management program and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants.
Our management, including our CISO, brings a wealth of knowledge and expertise to our company.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.