6 unchanged sentences
In addition, we regularly perform evaluations (including independent third-party evaluations) of our security program and our information technology infrastructure and information security management systems.
+Added: A retained independent third-party firm reviews the maturity of our information security program and the results are discussed annually in the Technology and Cybersecurity Committee of the Board.
Our processes also address risk and identification of cybersecurity threat risks from our use of third-party service providers .
This involves, among other things, conducting pre-engagement risk-based diligence, reviewing security and controls reports, implementing contractual security and notification provisions, and ongoing monitoring as needed.
−Removed: Our information security management system is based upon industry frameworks.
+Added: Our information security management system is based upon industry frameworks including but not limited to ISO 27001 and NIST Cybersecurity Framework.
Our Chief Information Security Officer (CISO) leads our cybersecurity program, which includes the implementation of controls designed to align with these industry frameworks and applicable statutes and regulations.
1 unchanged sentence
He has a Bachelor of Science in Computer Information Systems.
−Removed: We have implemented security monitoring capabilities designed to alert us to suspicious activity and developed an incident response program that includes periodic testing and is designed to restore business operations quickly.
+Added: We have implemented security monitoring capabilities designed to alert us to suspicious activity and developed an incident response program that includes an annual table top exercise and is designed to restore business operations quickly.
In addition, employees participate in mandatory annual training and receive communications regarding the cybersecurity environment to increase awareness throughout the company.
1 unchanged sentence
The Technology and Cybersecurity Committee of the Board has direct oversight to the Company’s (1) technology strategy, initiatives, and investments and (2) key cybersecurity information technology risks against both internal and external threats.
−Removed: The Technology and Cybersecurity Committee is comprised entirely of independent directors, all of whom have experience related to
−Removed: information security issues or oversight and meets and reports to the Board on a quarterly basis.
+Added: The Technology and Cybersecurity Committee is comprised entirely of independent directors, all of whom have experience related to information security issues or oversight and meets and reports to the Board on a quarterly basis.
The Audit Committee , which is also comprised entirely of independent directors, considers cybersecurity information technology risks in connection with overseeing our enterprise risk management system, and reports to the Board on enterprise risk management matters on a quarterly basis.
12 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.