15 unchanged sentences
Information is classified into four categories to help individuals apply the right level of controls and safeguards to information, applications and systems.
−Removed: In 2023, we conducted a mapping of the IISF with the NIST framework to make it easier for customers and other stakeholders to understand how IQVIA's cybersecurity program aligns with published frameworks.
Our global data centers and IT controls are included in an annual SOC2 Type II attestation program carried out by an independent audit firm who performs control testing and issues reports.
1 unchanged sentence
Additionally, our cybersecurity controls are regularly assessed as part of our global Internal Audit plan, and the maturity of our Information Security program is also regularly assessed on at least an annual basis with the help of independent consultants.
−Removed: Our internal Business Information Security Office ("BISO"), established in 2022, continues to streamline communications between our IT function and business units.
−Removed: The BISO connects several key functions, including the Chief Information Officer Business Partnership, business continuity, governance, risk management, and compliance.
Our cybersecurity program focuses on all areas of our business, including cloud-based environments, data centers, devices used by employees and contractors, facilities, networks, applications, vendors, disaster recovery / business continuity and controls and safeguards enabled through business processes and tools.
2 unchanged sentences
We draw on the knowledge and insight of external cybersecurity experts and vendors and employ an array of third party tools to secure IQVIA information infrastructure and protect systems and information from unauthorized access.
−Removed: We manage risk in our supply chain through engagement with suppliers and vendors, including vendor on-boarding risk assessments, ongoing oversight, and independent cyber-reputation score monitoring for key suppliers.
+Added: We manage risk in our supply chain through engagement with suppliers and vendors, including vendor on-boarding risk assessments and ongoing oversight.
Our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats, including as a result of previously identified cybersecurity incidents, but we cannot provide assurance that they will not be materially affected in the future by such risks or any future material incidents.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.