3 unchanged sentences
Since our company is externally managed, we rely upon the operational and investment risk oversight functions of our Manager and its affiliates.
−Removed: To mitigate risk from cyber threats, our Manager has a designated Global Chief Security Officer (“GCSO”) who leads the global security department that is responsible for identifying, assessing, and managing cybersecurity threats.
+Added: To mitigate risk from cyber threats, our Manager has a designated Global Chief Security Officer (“GCSO”) who leads its global security department that is responsible for identifying, assessing, and managing cybersecurity threats.
The GCSO has experience in the public and private sectors, specializing in security, investigations, and incident response.
−Removed: The global security department oversees the following groups across Invesco:
−Removed: Information Security, Global Privacy, Business Continuity & Crisis Management, Resilience and Corporate Security.
−Removed: This converged security structure supports a more comprehensive, holistic approach to keeping our and Invesco clients, employees, and critical assets safe, upholding privacy rights, while enabling a secure and resilient business.
−Removed: Our Manager’s information security program is led by its Chief Information Security Officer (“CISO”) who reports directly to the GCSO and has extensive experience in specializing in information security and risk management.
−Removed: Our Manager’s information security program is designed to oversee all aspects of information security risk and seeks to ensure the
−Removed: confidentiality, integrity, and availability of information assets, including the implementation of controls aligned with industry guidelines and applicable statutes and regulations to identify threats, detect attacks and protect its and our information assets.
+Added: The global security
+Added: department oversees the following groups across Invesco:
+Added: Information Security, Strategic Intelligence, Corporate Security, Business Continuity, Crisis Management, Global Privacy Office, Business Security, Projects and Strategy.
+Added: This structure supports a more comprehensive, holistic approach to keeping our and Invesco clients, employees, and critical assets safe, upholding privacy rights and enabling a secure and resilient business.
+Added: Our Manager’s information security program is led by its Chief Information Security Officer (“CISO”) who reports directly to the GCSO and has extensive experience in information security and risk management.
+Added: Our Manager’s information security program is designed to oversee all aspects of information security risk and seeks to ensure the confidentiality, integrity, and availability of information assets, including the implementation of controls aligned with industry guidelines and applicable statutes and regulations to identify threats, detect attacks and protect its and our information assets.
Our Manager's cybersecurity program includes the following:
• Proactive assessments of technical infrastructure and security resilience are performed on a regular basis which include penetration testing, offensive testing and maturity assessments.
−Removed: • Conducting due diligence on third-party service providers regarding cybersecurity risks prior to on-boarding, periodic assessment of cybersecurity risks for third-party service providers and continuous monitoring for new third-party cybersecurity incidents.
−Removed: • An incident response program that includes periodic testing and is designed to restore business operations as quickly and as orderly as possible in the event of a cybersecurity incident at Invesco or third-party incident.
+Added: • Conducting due diligence on third-party service providers regarding cybersecurity risks prior to on-boarding, periodic assessment of cybersecurity risks for existing third-party service providers and continuous monitoring for new third-party cybersecurity incidents.
+Added: • An incident response program that includes periodic testing and is designed to restore business operations as quickly and as orderly as possible in the event of a cybersecurity incident at Invesco or a third-party.
• Mandatory annual employee security awareness training, which focuses on cyber threats and security in general.
−Removed: • Regular cyber phishing tests throughout the year to measure and raise employee awareness against cyber phishing threats.
+Added: • Regular cyber phishing tests throughout the year to measure and raise employee awareness of cyber phishing threats.
Important to these programs is our Manager’s investment in threat-intelligence, its active engagement in industry and government security-related forums, and its utilization of external experts to challenge its program maturity, assess its controls and routinely test its capabilities.
11 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.