5 unchanged sentences
We leverage the following guidelines and frameworks to develop and maintain our Information Security Program:
−Removed: Federal Financial Institutions Examination Council ("FFIEC") Information Security IT Examination Handbook, FFIEC Business Continuity Planning Handbook, FFIEC Cybersecurity Assessment Tool, the Payment Card Industry Data Security Standard (“PCI DSS”), Center for Internet Security Critical Security Controls, National Institute of Standards and Technology Special Publication 800 Series, ISO-27000 Standard and GLBA 501(b).
+Added: Federal Financial Institutions Examination Council ("FFIEC") Information Security IT Examination Handbook, FFIEC Business Continuity Planning Handbook, the Payment Card Industry Data Security Standard
+Added: (“PCI DSS”), Center for Internet Security Critical Security Controls, National Institute of Standards and Technology Special Publication 800 Series, ISO-27000 Standard and GLBA 501(b).
Our Information Security Program includes an incident response plan to coordinate the activities we take to protect against, detect, respond to and remediate cybersecurity incidents, as such term is defined in Item 106(a) of Regulation S-K, as well as to comply with potentially applicable legal obligations and mitigate brand and reputational damage.
19 unchanged sentences
The Risk Committee of our Board of Directors provides structured oversight of the Company’s Enterprise Risk Management Program, including the oversight of risks from cybersecurity threats.
−Removed: The Risk Committee regularly receives an overview from management of our cybersecurity risk management and strategy processes covering topics such as data security posture, results from third-party assessments, progress towards pre-determined risk-mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks.
+Added: The Risk Committee regularly receives an overview from management of our cybersecurity risk management and strategy processes covering topics such as data security posture, results from third-party assessments, progress towards pre-determined risk-
+Added: mitigation-related goals, our incident response plan, and material cybersecurity threat risks or incidents and developments, as well as the steps management has taken to respond to such risks.
In such sessions, the Risk Committee generally receives materials including a cybersecurity scorecard and other materials indicating current and emerging material cybersecurity threat risks, and describing the company’s ability to mitigate those risks, and discusses such matters with our Chief Information Security Officer and Chief Technology Officer .
13 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.