3 unchanged sentences
We recognize the need to maintain the security and confidentiality of personal information, protected health information, and other confidential data that we collect and use in connection with our business, and the importance of assessing, identifying, and managing various cybersecurity risks that may impact our business.
−Removed: As such, we have implemented an information security program, which includes cybersecurity risk management measures intended to prevent, detect, and respond to malicious cyber activities and other security incidents that could adversely affect the confidentiality, integrity, or availability of our, or our customers’ information or information systems.
−Removed: Our information security program is designed based on the National Institute of Standards and Technology (“NIST”) 800-53 framework.
+Added: As such, we have implemented an information security program, which includes cybersecurity risk management measures intended to protect, detect, and respond to malicious cyber activities and other security incidents that could adversely affect the confidentiality, integrity, or availability of our, or our customers’ information or information systems.
+Added: Our information security program is designed based on the National Institute of Standards and Technology (“NIST”) Cybersecurity v2.0 framework.
This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use the NIST framework as a guide in designing and implementing our information security program.
3 unchanged sentences
(ii) an information security team principally responsible for managing our (1) information security risk assessment processes, (2) security controls, and (3) response to cybersecurity incidents;
−Removed: (iii) risk assessments and security tests, conducted internally and by external security and risk audit providers, as appropriate;
+Added: (iii) risk assessments and security tests, conducted internally and by external security and risk audit providers with subject matter expertise, as appropriate;
(iv) cybersecurity awareness training of our employees;
(v) a cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents;
−Removed: and (vi) third-party risk assessment procedures to review material third-party vendors and applications for information security.
+Added: and (vi) third-party risk assessment procedures to review key third-party vendors based on our assessment of their criticality to our operations and respective risk profile and applications for information security.
We have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially affected us, including our operations, business strategy, results of operations, or financial condition.
14 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.