2 unchanged sentences
The Corporation's cybersecurity risk management program is integrated into our enterprise risk management program and is designed to expeditiously identify, analyze and protect against security threats to its computer systems, software, networks, storage devices and other technology assets.
−Removed: Our management team, with input from our Board of Directors, proactively manages the Corporation's cybersecurity risks to avoid or minimize the impacts of attacks by unauthorized parties attempting to obtain access to confidential information, destroy data, disrupt service, sabotage systems or cause other damage.
+Added: Our management team, with oversight from our Board of Directors, proactively manages the Corporation's cybersecurity risks to avoid or minimize the impacts of attacks by unauthorized parties attempting to obtain access to confidential information, destroy data, disrupt service, sabotage systems or cause other damage.
Specifically, the Corporation has appointed a CISO to maintain a comprehensive information security program.
11 unchanged sentences
The Corporation's CISO and key members of management are members of the ICIRP.
−Removed: The Corporation provides the CISO and the information security team the latest tools and techniques to protect the confidentiality, integrity and availability of the Corporation's data for the benefit of our customers, employees and shareholders.
+Added: The Corporation provides the CISO and the information security team with a comprehensive suite of security tools and techniques to protect the confidentiality, integrity and availability of the Corporation's data for the benefit of our customers, employees and shareholders.
We periodically engage third-party consultants to assess the effectiveness of our strategy, tools and techniques, and overall information security program.
−Removed: Independent oversight and assurance activities specifically include internal audits, vulnerability assessments and penetration testing.
+Added: Independent oversight and assurance activities include internal audits, vulnerability assessments and penetration testing.
The Corporation's cybersecurity professionals are well-trained on how to protect customer and employee information through ongoing education and awareness initiatives.
14 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.