6 unchanged sentences
We have implemented a cybersecurity risk management program intended to protect the security and availability of our critical systems and information.
−Removed: Our program incorporates certain guiding principles from the National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”).
−Removed: This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
+Added: Our risk assessment process is modeled after the National Institute of Standards and Technology (“NIST”) Guide for Conducting Risk Assessments and is performed annually.
+Added: We may also elect to perform assessments more often based on material changes in business activities or other factors.
+Added: The results of our cybersecurity risk assessment aid in identifying potential cybersecurity risks and guiding the adoption of appropriate risk mitigation measures.
+Added: Our cybersecurity threat defense
+Added: approach incorporates certain guiding principles from the NIST Cybersecurity Framework (the “NIST Framework”).
+Added: This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the NIST Framework as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
Our program includes a cybersecurity incident response plan that consists of incident identification, classification, investigation and diagnosis, response, and recovery.
5 unchanged sentences
• obtaining independent and objective assessments by our internal audit department;
−Removed: • annual review of Service Organization Controls (“SOC”) reports from our critical third-party vendors based upon a determination of their relative importance and risk level;
+Added: • annual review of Service Organization Controls reports from our critical third-party vendors based upon a determination of their relative importance and risk level;
• implementing preventative and detective security tools;
5 unchanged sentences
Our board of directors has designated the audit committee to oversee our exposure to risk, including risks related to cybersecurity threats, and the steps management has taken to monitor and control such risks.
−Removed: The audit committee receives periodic updates from our Vice President – Information Systems on our cybersecurity program and potential material cybersecurity threats.
−Removed: The audit committee is regularly informed about (1) the results of independent and objective assessments of key components of our cybersecurity program as reported by our internal audit department and (2) material risks that could impact our operations or financial condition and the measures implemented to adequately mitigate relevant risks.
+Added: The audit committee receives periodic updates from our Vice President – Information Systems on our cybersecurity program, potential material cybersecurity threats, and results of the most recent cybersecurity risk assessment.
+Added: Additionally, t he audit committee is regularly informed about (1) the results of independent and objective assessments of key components of our cybersecurity program as reported by our internal audit department and (2) material risks that could impact our operations or financial condition and the measures implemented to adequately mitigate relevant risks.
The audit committee regularly reports to our board of directors regarding its activities, including those related to cybersecurity risk oversight, and members of our board of directors periodically discuss cybersecurity matters with members of management.
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.