6 unchanged sentences
To protect our information systems from cybersecurity threats, we use various information technology and cybersecurity tools to safeguard our systems and data, which help prevent, identify, escalate, investigate, remediate, respond and recover from identified vulnerabilities and cybersecurity incidents.
−Removed: As part of the Company's cybersecurity risk management program, we follow the National Institute of Standards and Technology ("NIST") Cybersecurity Framework ("CSF") to assess, identify and manage material risks that arise from cybersecurity threats.
+Added: As part of the Company's cybersecurity risk management program, we follow the National Institute of Standards and Technology Cybersecurity Framework to assess, identify and manage material risks that arise from cybersecurity threats.
Griffon's cybersecurity risk management program is closely tied to and integrated with the Company's overall enterprise risk management processes.
3 unchanged sentences
From time to time, Griffon engages external experts, including cybersecurity assessors, consultants, and/or auditors to evaluate cybersecurity measures and risk management processes.
−Removed: We also maintain a cyber incident response plan ("IRP") with the objective of (1) providing a structured and systematic incident response process for cybersecurity threats that affect us, (2) timely and effectively identifying, resolving and communicating cybersecurity incidents, and (3) managing internal and external communications and reporting.
+Added: We also maintain a cyber incident response plan with the objective of (1) providing a structured and systematic incident response process for cybersecurity threats that affect us, (2) timely and effectively identifying, resolving and communicating cybersecurity incidents, and (3) managing internal and external communications and reporting.
If a cybersecurity incident occurs, our incident response team ("IRT") is immediately notified, and Griffon management is informed about and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents impacting the Company.
10 unchanged sentences
The Audit Committee is also responsible for assessing the steps management has taken to monitor and control these risks and exposures, and evaluating guidelines and policies with respect to our cybersecurity risk assessment and risk management.
−Removed: The Audit Committee reviews our cybersecurity program with management and reports to the Board of Directors with respect to, and its review of, the program.
+Added: The Audit Committee reviews our cybersecurity program with management and reports to the Board of Directors with respect to, and regarding its review of, the program.
Cybersecurity reviews by the Audit Committee generally occur at least annually, or more frequently as determined to be necessary or advisable.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.