4 unchanged sentences
ISMS complies with a number of internationally recognized standards for information security, including the ISO 27001:2022 Standard for Information Security, AICPA System and Organization Controls 2 (SOC 2) for the criteria of Security and Availability;
−Removed: the Payment Card Industry Data Security Standard 4.0, or PCI DSS 4.0, the global standard for the payment card industry.
+Added: the Payment Card Industry Data Security Standard v4.0.1, or PCI DSS v4.0.1, the global standard for the payment card industry.
In accordance with these international standards, and included in the ISMS, is our cybersecurity incident response process and plan.
2 unchanged sentences
The Incident Response Team will conduct an assessment to determine the nature and scope of the incident and manages the incident in accordance with our incident response procedures until the incident is contained and resolved.
−Removed: The Incident Response Team will document findings and make them available to the Incident Classification Team, which is comprised of our CISO, Executive Vice President of Production Engineering, Chief Information Officer, Chief Legal & Compliance Officer, or CLO, Chief Operating Officer, Chief Financial Officer, and their respective delegates.
+Added: The Incident Response Team will document findings and make them available to the Incident Classification Team, which is comprised of our CISO, Executive Vice President of Production Engineering, Chief Information Officer, Chief Administrative & Legal Officer, or CALO, Chief Operating Officer, Chief Financial Officer, and their respective delegates.
The Incident Classification Team is responsible for assessing the incident and notifying members of our management and our Board.
−Removed: Our Chief Executive Officer, CLO, CISO and CFO, in conjunction with third-party experts , including outside legal counsel and our internal disclosure committee, are responsible for coordinating external communications and disclosures, including with the Securities and Exchange Commission.
+Added: Our Chief Executive Officer, CALO, CISO and CFO, in conjunction with their delegates and third-party experts , including outside legal counsel, are responsible for coordinating external communications and disclosures, including with the Securities and Exchange Commission and impacted third parties.
Our ISMS has a risk based formulation.
12 unchanged sentences
• a third-party risk management process for service providers, suppliers, and vendors, pursuant to which we require such third parties to maintain certain security controls and assess their compliance with these requirements;
−Removed: • independent third-party assessments and audits of our Information Security Management System, or ISMS, to monitor compliance with globally recognized information security standards, including ISO 27001:2013/2022, ISO 27017:2015 (cloud security best practices), PCI DSS 4.0, HIPAA HiTech, and the AICPA SOC 2 criteria for Security and Availability.
+Added: • independent third-party assessments and audits of our Information Security Management System, or ISMS, to monitor compliance with globally recognized information security standards, including ISO 27001:2022, ISO 27017:2015 (cloud security best practices), PCI DSS v4.0.1, HIPAA, and the AICPA SOC 2 criteria for Security and Availability.
We have not identified risks from known cybersecurity incidents, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition.
Our Board considers cybersecurity risk as part of its risk oversight function and the full Board has direct oversight of cybersecurity and other information technology risks as well as oversees management’s implementation of our cybersecurity risk management program.
−Removed: Several of our Board members have substantial cybersecurity experience and have experience in the field, including Ms.
−Removed: Julie Iskow, Ms.
−Removed: Sue Barsamian and Mr.
+Added: Several of our Board members have cybersecurity experience, including Michael Burdiek, Sue Barsamian, Julie Iskow, Sudhakar Ramakrishna and Maria Walker.
Our Board receives quarterly reports from management on our cybersecurity processes and risks.
11 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.