6 unchanged sentences
In addition, we regularly perform evaluations (including independent third-party evaluations) of our security program and our information technology infrastructure and information security management systems.
−Removed: A retained independent third-party firm reviews the maturity of our information security program and the results are discussed annually in the Technology and Cybersecurity Committee of the Board.
−Removed: Our processes also address risk and identification of cybersecurity threat risks from our use of third-party service providers .
−Removed: This involves, among other things, conducting pre-engagement risk-based diligence, reviewing security and controls reports, implementing contractual security and notification provisions, and ongoing monitoring as needed.
+Added: A retained independent third-party firm reviews the maturity of our information security program and the results are discussed with the Audit Committee of the Board.
+Added: Our processes also address the identification, assessment, and management of cybersecurity threat risks from our use of third-party service providers and other external vendors that support our products, services and internal operations .
+Added: This involves, among other things, conducting pre-engagement risk-based diligence, reviewing security and controls reports, implementing contractual security and notification provisions, and ongoing monitoring and periodic assessment, as appropriate, based on the nature of the services provided and changes in the threat environment.
Our information security management system is based upon industry frameworks including but not limited to ISO 27001 and NIST Cybersecurity Framework.
5 unchanged sentences
We also implemented an enhanced annual training program for specific specialized employee populations, including secure coding training.
−Removed: The Technology and Cybersecurity Committee of the Board has direct oversight to the Company’s (1) technology strategy, initiatives, and investments and (2) key cybersecurity information technology risks against both internal and external threats.
−Removed: The Technology and Cybersecurity Committee is comprised entirely of independent directors, all of whom have experience related to information security issues or oversight and meets and reports to the Board on a quarterly basis.
−Removed: The Audit Committee , which is also comprised entirely of independent directors, considers cybersecurity information technology risks in connection with overseeing our enterprise risk management system, and reports to the Board on enterprise risk management matters on a quarterly basis.
−Removed: We have processes in place for management to report security instances to the Technology and Cybersecurity Committee and Audit Committee as they occur, if material, and to provide a summary multiple times per year of other incidents to the Technology and Cybersecurity Committee.
−Removed: Additionally, our CISO attends each Technology and Cybersecurity Committee meeting and meets regularly with the Board of Directors or the Audit Committee of the Board of Directors to brief them on technology and information security matters.
+Added: The Audit Committee of the Board has direct oversight to the Company’s (1) technology strategy, initiatives, and investments and (2) key cybersecurity information technology risks against both internal and external threats.
+Added: The Audit Committee of the Board is comprised entirely of independent directors, with a mix of experience related to information technology audits, information security issues and/or oversight who meets and reports to the Board on a quarterly basis.
+Added: The Audit Committee considers information technology risks in connection with cybersecurity incidents overseeing our enterprise technology, and reports to the Board on enterprise risk management matters on a quarterly basis.
+Added: We have processes in place for management to report security instances to the Audit Committee as they occur, if material, and to provide a summary multiple times per year of other incidents to the Audit Committee.
+Added: Additionally, our CISO attends each Audit Committee meeting and meets regularly with the Board of Directors to brief them on technology and information security matters.
We carry insurance that provides protection against some of the potential losses arising from a cybersecurity incident.
1 unchanged sentence
This includes penalties and settlements, of which there were none.
−Removed: We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, under the heading “ Our solutions, systems, websites and the data on these sources have been in the past and may continue to be subject to cybersecurity events that could materially harm our reputation and future sales.
−Removed: ” included as part of ”Risk Factors” in Item 1A of this Annual Report on Form 10-K, which disclosures are incorporated by reference herein.
−Removed: Not applicable.
−Removed: Legal Proceedings
−Removed: Information with respect to this Item may be found under the heading “Litigation contingencies” in Note 18 of the Notes to the Consolidated Financial Statements in this Annual Report on Form 10-K which information is incorporated into this Item 3 by reference.
−Removed: Mine Safety Disclosures
−Removed: Not applicable.
+Added: We describe whether and how risks from identified cybersecurity threats, including as a result of any previous cybersecurity incidents, have materially affected or are reasonably likely to materially affect us, including our business strategy, results of operations, or financial condition, under the heading “Our solutions, systems, websites and the data on these sources have been in the past and may continue to be subject to cybersecurity events that could materially harm our reputation and future sales.” included as part of ”Risk Factors” in Item 1A of this Annual Report on Form 10-K, which disclosures are incorporated by reference herein.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.