2 unchanged sentences
Risk Management and Strategy
−Removed: Our Adviser and our Administrator have implemented ongoing processes that are designed to continually identify, assess, manage, monitor and mitigate the dynamic and evolving material risks to us from cybersecurity threats.
−Removed: Our Adviser’s and Administrator’s resource management and compliance departments work in conjunction with an independent third-party information technology service provider (“ISP”) engaged by our Adviser to manage our information technology strategy.
−Removed: The ISP regularly performs cyber assessments and assists in maintaining our cyber and information security programs.
−Removed: The ISP proposes recommendations for improvements to our Adviser’s resource management and compliance departments, which then are considered by other officers and employees of our Adviser and Administrator before implementation.
−Removed: In addition, regular ongoing cybersecurity threat risk assessments, which also cover third-party business applications, are performed throughout the year and reported to our officers and Board of Directors by our Chief Compliance Officer (“CCO”) no less than quarterly.
+Added: Our Adviser and Administrator have implemented ongoing processes that are designed to continually identify, assess, manage, monitor and mitigate the dynamic and evolving material risks to us from cybersecurity threats.
+Added: Our Adviser’s and Administrator’s resource management, information technology ("IT") and compliance departments work in conjunction with an independent third-party information technology service provider (“ISP”) engaged by our Adviser to manage our information technology strategy.
+Added: The ISP regularly performs cyber assessments and assists our Adviser and Administrator in monitoring our cyber and information security programs.
+Added: The ISP proposes recommendations for improvements to our Adviser’s Head of Resource Management, Director of IT and Chief Compliance Officer ("CCO"), which then are considered by other relevant officers of our Adviser and Administrator before implementation.
+Added: In addition, regular ongoing cybersecurity threat risk assessments, which also cover third-party business applications, are performed throughout the year and reported to our officers and Board of Directors by our CCO no less than quarterly.
Cybersecurity risks are assessed in general as part of the overall enterprise risk management for us, but also specifically between the ISP and our Adviser and Administrator in monitoring and determining not only the risks but also in assessing corresponding processes and procedures to mitigate those risks appropriately.
Our ISP constantly monitors information technology risk and cybersecurity threats globally.
−Removed: When risks are detected, we, through our Adviser and Administrator, consults with the ISP to assess if the risk is a cybersecurity threat to our information technology systems or data.
+Added: When risks are detected, the Director of IT, Head of Resource Management and CCO consult with the ISP to assess if the risk is a cybersecurity threat to our information technology systems or data.
If a risk to our information systems or data is identified, we, through our Adviser and Administrator, work in conjunction with the ISP to implement recommended processes, improvements, or safeguards to our systems or processes to address the risks as needed.
11 unchanged sentences
Contractually, we require the ISP to annually provide a third-party report on its systems and on the suitability of the design and operating effectiveness of its controls relevant to information and cyber security.
−Removed: In addition to the ongoing dialogue and technology interaction between our Adviser and Administrator and the ISP, any significant findings in these reports are shared with us, including our Board of Directors and other officers, to enhance ongoing monitoring and assessment of our information technology and cybersecurity risk management.
+Added: In addition to the ongoing dialogue and technology interaction between the Director of IT, our Adviser and Administrator and the ISP, any significant findings in these reports are shared with us, including our Board of Directors and other officers, to enhance ongoing monitoring and assessment of our information technology and cybersecurity risk management.
Our Adviser and Administrator also regularly trains employees working on our behalf on the evolving threats and educates them on cybersecurity risks to provide an additional protection barrier through end-user knowledge.
13 unchanged sentences
This includes identifying, assessing, mitigating, and monitoring cyber information security risks.
+Added: Our Director of IT has over 20 years of experience in IT, with a focus in the implementation of information security projects to enhance organizations' resilience against emerging threats and has collaborated closely with security vendors/partners to contain and address cybersecurity incidents.
These managers, as well as other management personnel, attend various professional continuing education programs, which include cybersecurity matters.
2 unchanged sentences
The Adviser is the current leaseholder of all properties in which we operate.
−Removed: We occupy these premises pursuant to our Advisory and Administration Agreements with the Adviser and Administrator, respectively.
+Added: We occupy these premises pursuant to our Advisory Agreement and Administration Agreement with the Adviser and Administrator, respectively.
LEGAL PROCEEDINGS
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.