42 unchanged sentences
Our cybersecurity program is evaluated regularly by both the internal audit function as well as third-party audit firms.
−Removed: These audits help ensure our program is appropriate to address the changing threat landscape and aligns to industry standards such as the National Institute of Standards and Technology Cybersecurity Framework, as well as other legal and regulatory guidance including the Federal Financial Institutions Examination Council Cybersecurity Assessment Tool, Conference of State Bank Supervisors Ransomware Self-Assessment Tool, the Gramm-Leach-Bliley Act and the Sarbanes-Oxley Act.
+Added: These audits help ensure our program is appropriate to address the changing threat landscape and aligns to industry standards such as the National Institute of Standards and Technology Cybersecurity Framework, Conference of State Bank Supervisors Ransomware Self-Assessment Tool, the Gramm-Leach-Bliley Act and the Sarbanes-Oxley Act.
Controls are reviewed for adequacy and design at least annually, and both internal and third-party audits aid in identifying areas for continued focus, providing assurance that controls are appropriately designed and operating effectively.
11 unchanged sentences
The Board and management define risk tolerances in the policies of the Company.
−Removed: The Board maintains oversight of risks from cybersecurity related threats, through various committees including the Audit and Risk Committee and the bank's Executive Risk Committee.
+Added: The Board maintains oversight of risks from cybersecurity related threats, primarily through the Audit and Risk Committee and the directors that serve on the bank's Executive Risk Committee.
The CISO reports to the Executive Risk Committee.
−Removed: The CISO provides periodic reports to directors that permit them to measure management’s compliance with the defined risk limits and to gauge the changing nature of risk inherent in the Company’s chosen lines of business and operations and as a result of changing factors within the Company, such as management and personnel changes, and technology changes.
+Added: The Company's Information Technology/Security Committee and the CISO provide periodic reports to directors that permit them to understand the cybersecurity risk landscape, assess the Company's strategies and resources for addressing cybersecurity threats, measure management’s compliance with the defined risk limits and gauge the changing nature of risk inherent in the Company’s chosen lines of business and operations and as a result of changing factors within the Company, such as management and personnel changes, and technology changes.
This includes an annual program update to the Executive Risk Committee and the Board.
15 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.