4 unchanged sentences
The Company’s Chief Information Security Officer (“CISO”), in concert with a Data Security Committee, is responsible for developing and implementing our enterprise information security program and reporting cybersecurity matters to senior management.
+Added: T he company's enterprise information security program adheres to the National Institute of Standards and Technology (NIST) Cybersecurity Framework 2.0 and other relevant industry frameworks as necessary.
Our risk management strategy encompasses a range of policies, procedures, and controls designed to safeguard our information assets.
Key elements of our risk management and control framework include Information Technology (“IT”) policies and procedures, employee training, annual disaster recovery tests, and penetration tests performed by third-party experts.
+Added: The Company also employs systems and processes designed to oversee and identify cybersecurity threats associated with third-party vendors.
The Company has established robust IT policies and procedures governing the use, access, and protection of our digital assets.
14 unchanged sentences
The Company’s Board of Directors oversees the processes for risk management, including cybersecurity risks, to help align risk exposure with strategic objectives.
−Removed: Senior manage ment, including our CISO, periodically briefs the Board of Directors on our cybersecurity framework and assessments of the information security program, key and emerging threats and risks, the status of projects to strengthen our information security systems, and any cybersecurity incidents that could potentially have a material business impact.
+Added: Senior manage ment periodically briefs the Board of Directors on our cybersecurity framework and assessments of the information security program, key and emerging threats and risks, the status of projects to strengthen our information security systems, and any cybersecurity incidents that could potentially have a material business impact.
In the event of an incident, the Company would follow a detailed incident response plan, which outlines the steps to be followed, including notification of senior management and the Board of Directors, as appropriate.
−Removed: Our CISO has 25 years of experience in the cybersecurity and technology space.
−Removed: Our Data Security Committee is composed of key business and functional stakeholders to include Risk, Legal, Finance, IT, Operations, and Business line leads.
+Added: Our CISO has more than 25 years of experience in the cybersecurity and technology space.
+Added: Our Data Security Committee is composed of key business and functional stakeholders including Risk, Legal, Finance, IT, Operations, and Business line leads.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.