Unresolved Staff Comments
−Removed: Leidos Holdings, Inc.
−Removed: Annual Report - 43
Cybersecurity
3 unchanged sentences
We maintain technologies, programs and processes designed to assess, identify, manage and mitigate cybersecurity risks.
−Removed: Our efforts include regular monitoring of Leidos-managed programs for internal and external cybersecurity threats, providing cybersecurity training to our employees during the onboarding process and annually, and continually reviewing and refining formal policies and procedures designed to deter, identify and remediate cybersecurity incidents.
+Added: Our efforts include regular monitoring of Leidos-managed systems and networks for internal and external cybersecurity threats, providing cybersecurity training to our employees during the onboarding process and annually, and continually reviewing and refining formal policies and procedures designed to deter, identify and remediate cybersecurity incidents.
We regularly perform evaluations of our cybersecurity program and continue to invest in our capabilities to keep our customers, partners, suppliers and information assets in our possession safe.
5 unchanged sentences
Leidos CSIRT also provides intrusion monitoring of networks and information systems and continuously monitors the Leidos computing environments and performs triage and analysis of events to identify potential incidents.
−Removed: We employ multiple security and monitoring devices and applications throughout the Company to identify, alert, report and log all authorized and unauthorized access to the Leidos enterprise networks.
+Added: We employ multiple security and monitoring systems and applications throughout the Company to identify, alert, report and log authorized and unauthorized access to the Leidos systems and networks.
We use an application that collects, correlates, and notifies CSIRT analysts regarding any item meeting an electronic intrusion event.
2 unchanged sentences
We also conduct periodic internal and third-party assessments to test our cybersecurity controls, perform cyber simulations and exercises, and continually evaluate our internal governing policies and procedures to help detect and respond to cybersecurity events in order to reduce harms or impacts from breaches and other information security incidents.
+Added: Leidos Holdings, Inc.
+Added: Annual Report
MANAGEMENT’S RESPONSIBILITIES
4 unchanged sentences
Additionally, we have a Leidos Security Council that is co-chaired by the Chief Information Security Officer and the Chief Security Officer to address “all security hazards” across our global enterprise to ensure cohesion and effectiveness of our combined security governance and risk mitigations.
−Removed: Leidos Holdings, Inc.
−Removed: Annual Report - 44
BOARD’S ROLES AND RESPONSIBILITIES
−Removed: We have a Technology and Innovation Security Committee, comprised of six board members, with relevant backgrounds and experience, that oversees and advises the Board and management on matters involving the Company’s overall strategic direction and significant business risks and opportunities in the areas of technology and information security.
+Added: We have a Technology and Information Security Committee , comprised of six board members, with relevant backgrounds and experience, that oversees and advises the Board and management on matters involving the Company’s overall strategic direction and significant business risks and opportunities in the areas of technology and information security.
At least quarterly, management provides our Board and the Technology and Information Security Committee with updates about our cybersecurity and related risk exposures, our policies and procedures to mitigate such exposures and the status of projects to strengthen our information security infrastructure and program maturity and defend against and respond to cybersecurity threats.
4 unchanged sentences
For more information about these risks, please see “Risk Factors – Cybersecurity breaches and other information security incidents could negatively impact our business and financial results, impair our ability to effectively provide our services to our customers and cause harm to our reputation or competitive position” in this Annual Report on Form 10-K.
−Removed: Leidos Holdings, Inc.
−Removed: Annual Report - 45
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.