17 unchanged sentences
Restorations from these systems are tested on a quarterly basis.
−Removed: We use external third parties to perform annual security assessments such as penetration testing and vulnerability scans for both our internal network and critical online systems.
+Added: We use a third party to perform annual security assessments .
+Added: This includes both external penetration testing and internal vulnerability testing, as well as a security program maturity assessment based on the NIST framework (National Institute of Standards and Technology).
+Added: External testing consists of scanning all our public IP addresses for open ports and determining if any device or service on those ports have known vulnerabilities.
+Added: Internal vulnerability testing is performed from within the network to determine if any known vulnerabilities exist due to outdated patches or insecure configurations.
+Added: The security program maturity assessment is a review of our policies and practices against a set of standard best practice controls identified by the NIST to determine a maturity level score.
+Added: We use this assessment to focus our efforts on continually improving our cybersecurity policies and practices.
We currently do not have any formal processes to oversee or identify cybersecurity risks associated with third-party service providers but our Director of Information Technology generally evaluates such risks.
12 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.