6 unchanged sentences
GLDM also relies on the cybersecurity programs of its service providers.
−Removed: The Board of Directors of the Sponsor (the “Board of Directors”) receives reports from the Sponsor detailing the Sponsor's cybersecurity review processes, any potential risks and any incidents which could impact GLDM.
+Added: The Board of Directors of the Sponsor (the “Board of Directors”) receives reports from the Sponsor's officers detailing the Sponsor's cybersecurity review processes, any potential risks and any incidents which could impact GLDM.
The Board of Directors also periodically receives, and reviews reports from the World Gold Council and GLDM’s service providers regarding their cybersecurity programs.
2 unchanged sentences
Cybersecurity Program Overview
−Removed: The World Gold Council has a comprehensive cybersecurity program built around the National Institute of Standards and Technology’s Cybersecurity Framework which is overseen by the World Gold Council’s Global Head of IT.
+Added: The World Gold Council has a comprehensive cybersecurity program built around the National Institute of Standards and Technology’s Cybersecurity Framework which is overseen by the World Gold Council’s Chief Technology Officer.
The program incorporates a variety of strategies and measures aimed at identifying, protecting, detecting, responding to and recovering from cyber incidents.
−Removed: The program’s key components include risk assessment and management, where the Operational Risk Committe of the World Gold Council, of which the Principal Financial and Accounting Officer of the Sponsor is a member, identifies potential threats and vulnerabilities and implements appropriate controls to mitigate those vulnerabilities.
−Removed: As part of the program, the World Gold Council (1) develops and enforces security policies and procedures, providing guidelines for safe and secure operations, (2) prioritizes employee training and awareness, as human error is often a significant factor in security breaches, (3) conducts regular security audits and assessments to ensure that the program remains effective and up to date with evolving threats, and (4) incorporates advanced technologies such as identify management, encryption, firewalls, anti-malware and intrusion detection systems to provide multiple layers of defense against cyber-attacks.
+Added: The program’s key components include risk assessment and management, where the Operational Risk Committee of the World Gold Council, of which the Principal Financial and Accounting Officer of the Sponsor is a member, identifies potential threats and vulnerabilities and implements appropriate controls to mitigate those vulnerabilities.
+Added: As part of the program, the World Gold Council (1) develops and enforces security policies and procedures, providing guidelines for safe and secure operations, (2) prioritizes employee training and awareness, as human error is often a significant factor in security breaches, (3) conducts regular security audits and assessments to ensure that the program remains effective and up to date with evolving threats, and (4) incorporates advanced technologies such as identity management, encryption, firewalls, anti-malware and intrusion detection systems to provide multiple layers of defense against cyber-attacks.
The World Gold Council has an incident response plan (“IRP”) which (1) identifies the incident response team and the roles and responsibilities of the team members, (2) details the incident response lifecycle, including preparation, detection, response and recovery, and (3) outlines the internal and external communications plan.
2 unchanged sentences
Management ’ s Role in Cybersecurity Risk Management
−Removed: The Sponsor conducts annual due diligence on GLDM’s service providers, including the Administrator and Custodians, which includes a revise of the relevant service provider's operational and cybersecurity controls.
−Removed: The Sponsor reviews and reports to the Board of Directors, the results of this annual review and any incidents or perceived risks.
+Added: The Sponsor conducts annual due diligence on GLDM’s service providers, including the Administrator and Custodians, which includes a review of the relevant service provider's operational and cybersecurity controls.
+Added: The Sponsor's officers review and report the results of this annual review and any incidents or perceived risks to the Board of Directors.
Board Oversight of Cybersecurity Risks
−Removed: The Board of Directors receives a report from the Sponsor detailing the Sponsor's annual due diligence on GLDM's service providers, including a summary of any potential operational or cybersecurity risks and any incidents which could impact GLDM.
−Removed: The Board of Directors also periodically receives reports from World Gold Council and GLDM’s service providers regarding their cybersecurity programs.
+Added: The Board of Directors receives a report from the Sponsor's officers detailing the Sponsor's annual due diligence on GLDM's service providers, including a summary of any potential operational or cybersecurity risks and any incidents which could impact GLDM.
+Added: The Board of Directors also periodically receives reports from the World Gold Council and GLDM’s service providers regarding their cybersecurity programs.
Not applicable.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.