3 unchanged sentences
We have an enterprise-wide risk management framework for identifying, assessing, managing, monitoring, and reporting our material risks, including cybersecurity risks.
−Removed: Our risk identification and risk and control self-assessment ("RCSA") process assesses the potential likelihood and impact of, among other things, cybersecurity risks to the Company, and the control environment in place to mitigate identified risks.
−Removed: Risk Factors – “ Risks Related to Information Technology, Security and Data” for a description of the cybersecurity risks we face.
+Added: Our risk identification and risk and control self-assessment process assesses the potential likelihood and impact of, among other things, cybersecurity risks to the Company, and the control environment in place to mitigate identified risks.
+Added: Risk Factors – “ Risks Related to Information Technology, Security, Artificial Intelligence, and Data” for a description of the cybersecurity risks we face.
The Company is committed to attaining the highest standards for information security and data privacy programs through disciplined governance and risk management practices.
17 unchanged sentences
JFI’s Board approved both the Company’s initial JFI Information Security Policy and the JFI Privacy Policy.
+Added: Our Chief Information Security Officer (“ CISO ”) regularly updates our Board on cybersecurity threats, risks, policy updates, incidents, and remediation actions.
The Finance and Risk Committee of the JFI Board assists the Board with oversight of the Company’s risk framework and its effectiveness.
1 unchanged sentence
The committee also reviews activity reports on the status of our cybersecurity program, including material policy changes, breaches, and remediation actions.
−Removed: At least annually, and more often as needed, the committee meets with our Chief Information Security Officer (“CISO”) in a dedicated session to review and discuss in-depth cybersecurity risks facing the Company.
−Removed: JFI’s Board of Directors receives periodic reports from its Finance and Risk Committee regarding the committee’s actions in respect of cybersecurity and related regulatory developments and receives from our CISO regular updates about cybersecurity threats and our cybersecurity and privacy programs.
+Added: Our chief risk officer provides a risk report quarterly to the committee that includes reporting on cybersecurity as a non-financial/operational risk.
+Added: JFI’s Board of Directors receives periodic reports from its Finance and Risk Committee regarding the committee’s actions in respect of cybersecurity and related regulatory developments.
Management’s Role in Assessing and Managing Material Risks from Cybersecurity Threats:
Our CISO is a member of the senior leadership team and oversees our Information Security and Privacy Team.
−Removed: The CISO provides regular updates to the Board on cybersecurity threats facing the organization, including developments in our ongoing information security and privacy programs.
−Removed: As noted, the CISO meets in dedicated sessions with the Finance and Risk Committee to review and discuss in-depth cybersecurity risks facing the Company.
+Added: The CISO provides updates to the Board on cybersecurity threats facing the organization, including developments in our ongoing information security and privacy programs.
+Added: The CISO also meets in dedicated sessions with the Finance and Risk Committee to review and discuss in-depth cybersecurity risks facing the Company.
Our Information Security and Privacy Team includes over 70 full-time positions with at least 50% of our associates holding relevant industry certifications, such as the Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and Certified Information Privacy Professional (CIPP).
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.