56 unchanged sentences
The Board and management define risk tolerances in the policies of the Company.
−Removed: The Board maintains oversight of risks from cybersecurity related threats, primarily through the Audit and Risk Committee and the directors that serve on the bank's Executive Risk Committee.
+Added: The Board maintains oversight of risks from cybersecurity related threats primarily through the Executive Risk Committee, as well as directors that serve on the bank’s Audit and Risk Committee.
+Added: Additionally, the Audit and Risk Committee review internal audit reports related to cybersecurity topics.
The CISO reports to the Executive Risk Committee.
9 unchanged sentences
The Information Technology/Security Committee (“ITSC”) is a management level committee that serves at the direction of the Board and provides oversight of the Company’s information technology and information security programs.
−Removed: The members of the ITSC include management and leaders with an expansive background in information technology and cybersecurity.
+Added: The members of the ITSC have extensive experience in banking, information technology, and cybersecurity, and include management, business leaders, CTO, and CISO.
The ITSC meets monthly to review information security and information technology reports and issues.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.