10 unchanged sentences
• All team members are empowered to submit self-identified information security risks for analysis by our internal risk management professionals.
−Removed: Cybersecurity risks identified through any of the foregoing mechanisms and submitted to our governance, risk, and compliance platform are assessed by our internal risk management professionals, in collaboration with appropriate subject-matter experts ("SMEs"), pursuant to standards established by our Enterprise Risk Management ("ERM") organization.
+Added: Cybersecurity risks identified through any of the foregoing mechanisms and submitted to our governance, risk, and compliance platforms are assessed by our internal risk management professionals, in collaboration with appropriate subject-matter experts ("SMEs"), pursuant to standards established by our Global Risk Management ("GRM") organization.
Our internal risk management professionals work with the SMEs and other stakeholders to establish remediation plans for identified information security risks and to determine when risk acceptance might be a reasonable and appropriate solution.
4 unchanged sentences
The information security program is under the responsibility of the Chief Information Security Officer ("CISO"), while governance and oversight is provided by the Technology Committee as set forth in the Technology Committee Charter.
−Removed: The CISO is responsible for assessing and managing risk from cybersecurity threats, as well as the strategy, execution and administration of the program, and reports directly to the Chief Information Officer ("CIO"), while also maintaining reporting lines to the Technology Committee, its chair and the full board of directors.
−Removed: Our CIO has over 25 years of experience specializing in cloud migrations, launching innovative software products and advanced analytics as well as building high-performance development organizations.
+Added: The CISO is responsible for assessing and managing risk from cybersecurity threats, as well as the strategy, execution and administration of the program, and reports directly to the Chief Technology Officer ("CTO"), while also maintaining reporting lines to the Technology Committee, its chair and the full Board of Directors.
+Added: Our CTO has extensive experience specializing in cloud migrations, launching innovative software products and advanced analytics as well as building high-performance development organizations.
Our CISO has over 25 years of leadership experience managing global information technology, information security and IT infrastructure and operations.
We have also established a Management Risk Committee ("MRC"), composed primarily of executive management, which meets regularly and is responsible for identifying, assessing, prioritizing and monitoring action plans to mitigate key risks.
−Removed: Lastly, our ERM organization, under the supervision of the Chief Risk Officer, leads our efforts to consider and assess threats to us and the risks that result therefrom, including cybersecurity threats and related risks.
−Removed: With support from the Information Security, Legal and the Privacy Office teams, our ERM organization conducts periodic evaluations of our information security posture, manages regular meetings with the executive leadership team to discuss risk levels across the Company, and maintains and monitors risk tolerances and escalation criteria that drive executive and the board of director communications, as further described in our disclosures related to the board of directors oversight of material risks associated with cybersecurity threats.
+Added: Our GRM organization, under the supervision of the Chief Risk Officer, leads our efforts to consider and assess threats to us and the risks that result therefrom, including cybersecurity threats and related risks.
+Added: With support from the Information Security, Legal and Privacy teams, our GRM organization conducts periodic evaluations of our information security posture, manages regular meetings with the executive leadership team to discuss risk levels across the Company, and maintains and monitors risk tolerances and escalation criteria that drive executive and the board of director communications, as further described in our disclosures related to the Board of Directors oversight of material risks associated with cybersecurity threats.
To encourage alignment on risk identification, assessment, and management objectives throughout all levels of the Company, we have implemented a security education and awareness program that is designed to reinforce key behaviors that facilitate risk reduction and inform team members about the material cybersecurity risks facing our organization.
5 unchanged sentences
and (2) requiring new software integrations and connectivity with vendors to undergo an architectural review process that involves consultation with the information security function and other relevant stakeholders.
−Removed: Moreover, critical vendors receive periodic comprehensive risk assessments conducted by the vendor management office (a team within the ERM organization), in collaboration with Information Security and our Business Resiliency Governance ("BRG") team, that include a focus on the vendor’s cybersecurity practices.
+Added: Moreover, critical vendors receive periodic comprehensive risk assessments conducted by the vendor management office (a team within the GRM organization), in collaboration with Information Security and our Business Resiliency Governance ("BRG") team, that include a focus on the vendor’s cybersecurity practices.
Evaluation, Categorization, and Escalation of Cybersecurity Incidents
−Removed: Our information security program includes an incident response plan, which establishes (1) a framework for classifying security incidents according to their severity level, taking into account the nature and scope of the incident;
+Added: Our information security program includes an incident response plan that establishes (1) a framework for classifying security incidents according to their severity level, taking into account the nature and scope of the incident;
and (2) protocols for the escalation of incidents, including to the attention of the Technology Committee as appropriate.
4 unchanged sentences
Discussion of Material Cybersecurity Risks and Incidents
−Removed: We have not experienced any material cybersecurity incidents in the past calendar year and the expenses we have incurred from cybersecurity incidents during that period were immaterial.
+Added: We have not experienced any material cybersecurity incidents in the past calendar year and the expenses we have incurred from cybersecurity incidents during that period were not material.
We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us, including our operations, business strategy, results of operations or financial condition.
6 unchanged sentences
At every regular meeting of the Technology Committee, the CISO provides the Technology Committee with updates and changes to the state, strategy and risks related to the information security program as well as other security news and topics.
−Removed: Further, the Technology Committee and Audit Committee of the board of directors receive quarterly reports from the Chief Risk Officer regarding our risk exposure related to significant information technology and information security practices.
−Removed: The CISO and CIO meet regularly with the chair of the Technology Committee outside of committee meetings.
−Removed: In addition, the board of directors regularly receives information about these topics from the chair of the Technology Committee, the CIO, and management, and the board of directors is apprised directly of incidents as appropriate, pursuant to our incident response plan.
+Added: Further, the Technology Committee and the Audit Committee of the Board of Directors receive quarterly reports from the Chief Risk Officer regarding our risk exposure related to significant information technology and information security practices.
+Added: The CISO and CTO meet regularly with the chair of the Technology Committee outside of committee meetings.
+Added: In addition, the Board of Directors regularly receives information about these topics from the chair of the Technology Committee, the CTO, and management, and the Board of Directors is apprised directly of incidents as appropriate, pursuant to our incident response plan.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.