7 unchanged sentences
Our risk assessment process is modeled after the National Institute of Standards and Technology (“NIST”) Guide for Conducting Risk Assessments and is performed annually.
−Removed: We may also elect to perform assessments more often based on material changes in business activities or other factors.
+Added: We may also elect to perform assessments more often
+Added: based on material changes in business activities or other factors.
The results of our cybersecurity risk assessment aid in identifying potential cybersecurity risks and guiding the adoption of appropriate risk mitigation measures.
−Removed: Our cybersecurity threat defense
−Removed: approach incorporates certain guiding principles from the NIST Cybersecurity Framework (the “NIST Framework”).
+Added: Our cybersecurity threat defense approach incorporates certain guiding principles from the NIST Cybersecurity Framework (the “NIST Framework”).
This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the NIST Framework as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
Our program includes a cybersecurity incident response plan that consists of incident identification, classification, investigation and diagnosis, response, and recovery.
+Added: Following our acquisition of the Hearthstone Venture, we have been integrating the Hearthstone Venture’s information technology environment and related cybersecurity systems and processes into our enterprise cybersecurity program.
+Added: Until integration is complete, certain Hearthstone Venture systems and controls operate under their pre-acquisition cybersecurity framework, which may differ from our established standards.
Our process for managing cybersecurity risk is a collaborative effort that includes key members of our information technology, legal, and finance departments, as well as internal audit and third-party cybersecurity firms.
19 unchanged sentences
The security committee oversees our cybersecurity incident response plan and is responsible for assessing and managing cybersecurity threats and evaluating the potential impact of such threats on our business strategy, results of operations, and overall financial condition.
+Added: The security committee is also overseeing the integration of the Hearthstone Venture systems and cybersecurity processes into our enterprise cybersecurity risk management and governance model.
The security committee supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us;
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.