4 unchanged sentences
The Company adheres to cybersecurity industry best practices such as the National Institute of Standards and Technology cybersecurity framework and Federal Financial Institutions Examinations Council ("FFIEC") guidance.
−Removed: FNWB management has integrated its processes for assessing, identifying, and managing material risks from cybersecurity threats into the Company’s overall risk management program, including regularly conducting risk assessments and gap analyses in order to identify and prioritize cybersecurity threats and vulnerabilities across our entire digital estate which is comprised of our IT infrastructure as well cloud-based applications and storage.
+Added: The Company conducted a NIST cybersecurity framework version 1 to version 2 gap analysis and is in the process of updating controls to adhere to the newest version.
+Added: Company management has integrated its processes for assessing, identifying, and managing material risks from cybersecurity threats into the Company’s overall risk management program, including regularly conducting risk assessments and gap analyses in order to identify and prioritize cybersecurity threats and vulnerabilities across our entire digital estate which is comprised of our IT infrastructure as well cloud-based applications and storage.
These assessments consider industry best practices, evolving threats, and the specific needs of our business.
6 unchanged sentences
The Company has a well-defined and mature vendor management program that includes controls to address third -party cybersecurity risks throughout the vendor management lifecycle.
−Removed: The FNWB Board of Directors has oversight responsibility for enterprise-wide risks, including cybersecurity risks.
−Removed: The Board recently welcomed a cybersecurity expert as a director to help further understand and anticipate risks in this area.
−Removed: A designated committee of the Board, the Audit Committee, is responsible for overseeing the Company's cybersecurity risk management program and reviewing its effectiveness.
−Removed: The Chief Information Officer and Security Officer ("CIO/SO") is responsible for assessing and managing material risks from cybersecurity threats, with a dedicated staff of information security professionals.
−Removed: The CIO/SO has over 25 years of education, training, and experience managing technology and cybersecurity risks, and over 12 years of experience in the banking industry specifically.
−Removed: The CIO/SO regularly updates executive and senior management, including the Enterprise Risk Management Committee, as well as the Board Audit Committee on cybersecurity risks and mitigation strategies.
+Added: The Board has oversight responsibility for enterprise-wide risks, including cybersecurity risks.
+Added: The Audit Committee, a designated committee of the Board, is responsible for overseeing the Company's cybersecurity risk management program and reviewing its effectiveness.
+Added: The Information Security Officer ("ISO") is responsible for assessing and managing material risks from cybersecurity threats, with a dedicated staff of internal and external information security professionals.
+Added: The ISO is a Systems Security Certified Practitioner and Certified Information Systems Security Professional with over 12 years of education, training and experience managing technology and cybersecurity risks, including eight years of experience in the banking industry specifically.
+Added: The ISO regularly updates executive and senior management, including the Bank's Enterprise Risk Management Committee, as well as the Board Audit Committee on cybersecurity risks and mitigation strategies.
The Company has implemented internal controls to address the effectiveness of our cybersecurity program.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.