4 unchanged sentences
management is responsible for assessing and managing our short- and long-term risk exposures, and our Board and its committees provide effective oversight through independent monitoring of strategic risks and regularly scheduled meetings with management to discuss in-depth the strategic objectives of the Company and associated risks.
−Removed: In order to maintain effective Board oversight across the entire enterprise risk management program, the Board delegates to the individual committees certain elements of its oversight function.
+Added: In connection with Board oversight across the entire enterprise risk management program, the Board delegates to the individual committees certain elements of its oversight function.
The Audit Committee of the Board has oversight of cybersecurity risk and receives regular updates on any developments from our Chief Information Security Officer (“CISO”) , including biannual updates on strategies and action plans, with periodic reports provided to our full Board.
1 unchanged sentence
Cybersecurity is a standing item on our Enterprise Risk Council agenda and our cybersecurity team regularly presents its work to the Enterprise Risk Council to enable evolving risks to be integrated into our management processes.
−Removed: All cybersecurity processes and frameworks are created by the Global Information Security team, led by our CISO.
−Removed: Our CISO has a Systems Engineer degree in Computer Science from St.
−Removed: Petersburg University of Information Technology and gained experience in the manufacturing, consultancy, and energy industries prior to joining the Company in 2012.
−Removed: Our CISO is a Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Information Technology Infrastructure Library (ITIL) v3 Expert, and Certified in Risk and Information Systems Control (CRISC).
−Removed: Our Integrated Information Security Framework ("IISF") defines the policies and processes we have in place to safeguard proprietary and confidential information.
+Added: The Global Information Security team, led by our CISO, create cybersecurity processes and frameworks for use throughout IQVIA.
+Added: Our CISO is an experienced cybersecurity leader with over 25 years of experience in security, technology and risk management, and has previously served as a public company CISO for a global financial services firm, where he spent 18 years serving in roles of increasing responsibility, leading large cross functional security and technology teams.
+Added: The IQVIA cybersecurity program employs policies, procedures, guidelines, training, communications, tools, assessments and other methods and resources to identify and manage cybersecurity risks.
+Added: Our Integrated Information Security Framework ("IISF") defines minimum controls and safeguards used to safeguard proprietary and confidential information.
Our IISF is based on relevant industry frameworks and laws, including, but not limited to National Institute of Standards and Technology ("NIST"), Good Practices Quality Guidelines (GxP), Health Information Trust Alliance (HITRUST), the ISMS Family of Standards (ISO 27000 family), Control Objectives for Information Technologies (COBIT), the EU General Data Protection Regulation (GDPR), and the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
−Removed: The framework consists of policies, standards, procedures, work instructions and documentation.
+Added: The framework is integrated with IQVIA policies, standards, procedures, work instructions, documentation and development and oversight activities.
Information is classified into four categories to help individuals apply the right level of controls and safeguards to information, applications and systems.
−Removed: In 2023, we conducted a mapping with the NIST to align our procedures with industry standards in an effort to create a first-in-class approach.
−Removed: Our global data centers and IT controls are included in an annual SOC2 Type II attestation program carried out by an independent audit firm who performs control testing and issue reports.
+Added: In 2023, we conducted a mapping of the IISF with the NIST framework to make it easier for customers and other stakeholders to understand how IQVIA's cybersecurity program aligns with published frameworks.
+Added: Our global data centers and IT controls are included in an annual SOC2 Type II attestation program carried out by an independent audit firm who performs control testing and issues reports.
Our set of SOC2 controls is aligned with ISO27001 specification and therefore provides an equivalent level of assurance on a global level.
1 unchanged sentence
Our internal Business Information Security Office ("BISO"), established in 2022, continues to streamline communications between our IT function and business units.
−Removed: The BISO connects several key functions, including Chief Information Officer Business Partnership, business continuity, governance, risk, and compliance.
+Added: The BISO connects several key functions, including the Chief Information Officer Business Partnership, business continuity, governance, risk management, and compliance.
Our cybersecurity program focuses on all areas of our business, including cloud-based environments, data centers, devices used by employees and contractors, facilities, networks, applications, vendors, disaster recovery / business continuity and controls and safeguards enabled through business processes and tools.
8 unchanged sentences
Non-technical safeguards also play an important role in our cybersecurity program.
−Removed: We provide various training programs and tools to employees so they can avoid risky practices and help us promptly identify potential or actual issues.
−Removed: We also have global incident response procedures, global service tools to log incidents and issues for investigation, and an ethics line to report concerns and follow-up on matters already reported.
+Added: We provide standard operating procedures, work instructions, guidelines, communications, training programs, tools and other documentation and resources to help employees avoid risky practices, help us promptly identify potential or actual issues and employ cybersecurity requirements in their day-to-day work We also have global incident response procedures, global service tools to log incidents and issues for investigation, and an ethics line to report concerns and follow-up on matters already reported.
For more information on our cybersecurity related risks, see Item 1A Risk Factors in this Annual Report on Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.