5 unchanged sentences
The Enterprise Risk Committee (“ERC”), which includes members of management of the Sponsor, receives regular reports from the CISO on, among other things, the Sponsor’s cyber risks and threats, the status of projects to strengthen the Sponsor’s information security systems, assessments of the Sponsor’s security program and the emerging threat landscape.
−Removed: The CISO updates the ERC and the Board quarterly.
−Removed: These regular reports include the Sponsor’s performance preparing for, preventing, detecting, responding to, and recovering from, cyber incidents.
−Removed: The CISO also promptly informs and updates the ERC and the Board about any information security incidents that may pose a material risk to the Sponsor.
−Removed: The Sponsor contracts an independent third party to conduct a full cyber risk assessment annually, and the results of those assessments are reported to the ERC and the Board.
−Removed: Material outcomes from any penetration testing, vulnerability scanning, and business continuity or disaster recovery testing are additionally reported to the ERC and Board.
+Added: The ERC provides updates to the Board quarterly, including on changes to security risks and outcomes.
+Added: The CISO also promptly informs and updates the ERC and the Board of the Sponsor about any information security incidents that may pose a material risk to the Sponsor.
+Added: The Sponsor contracts an independent third party to conduct a full cyber risk assessment annually, and the results of those assessments are included in reporting to the ERC and the Board.
+Added: Material outcomes from any penetration testing, vulnerability scanning, and business continuity or disaster recovery testing are additionally included in reporting to the ERC and Board .
The Sponsor’s Security Awareness Program includes training that reinforces the Sponsor’s Information Security policies, standards, and practices, and the expectation that employees will comply with these policies.
2 unchanged sentences
The Sponsor administers a Third-Party Risk Management Program at the firm to identify , assess and oversee the risk associated with service providers and third parties involved in the supply chain.
−Removed: Third parties are risk-rated and must adhere to additional security diligence requirements administered with oversight from the CISO according to risk, including cybersecurity diligence questionnaires, evidence validation, SOC report reviews, and/or on-site assessments.
+Added: Third parties are assessed for risk and may additionally be required to adhere to additional security diligence requirements administered with oversight from the CISO according to risk, including cybersecurity diligence questionnaires, evidence validation, SOC report reviews, and/or on-site assessments.
Material changes to the program, new, or worsening security risks associated with third parties are reported to the ERC at least quarterly.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.