7 unchanged sentences
In addition, members of our cybersecurity team have cybersecurity experience or certifications, such as the Certified Information Systems Security Professional certification.
−Removed: Our CIO is informed about and
−Removed: monitors prevention, detection, mitigation, and remediation efforts through regular communication and reporting from
−Removed: professionals on the cybersecurity management team and through the use of technological tools and software.
+Added: Our CIO is informed about and monitors prevention, detection, mitigation, and remediation efforts through regular communication and reporting from professionals on the cybersecurity management team and through the use of technological tools and software.
Policies, procedures and controls under our cybersecurity program are designed in consideration of published frameworks, including the Center for Information Security ("CIS") Critical Security Controls, and routinely evaluated for ongoing adherence to those frameworks.
Our cybersecurity program includes a process for incident response and continuous improvement.
−Removed: We enlist outside advisors to evaluate the maturity of our cybersecurity program, review processes and policies, conduct penetration and vulnerability tests and simulation exercises, and to monitor and help identify potential cybersecurity incidents.
−Removed: We provide training to our employees to help identify potential cybersecurity threats and attacks through an annual cybersecurity awareness month and targeted phishing campaigns.
+Added: We periodically enlist outside advisors to evaluate the maturity of our cybersecurity program, review processes and policies, conduct penetration and vulnerability tests and simulation exercises, and to monitor and help identify potential cybersecurity incidents.
+Added: We provide annual cybersecurity awareness training to our employees and contractors to help identify potential cybersecurity threats and attacks, perform targeted phishing campaigns, use multifactor authentication for secure access to our systems and networks and tabletop exercises to simulate and prepare for potential incidents.
When considering to engage with third-party service providers, we assess the risks from cybersecurity threats posed by such engagement and continue to evaluate those risks throughout the duration of the relationship.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.