38 unchanged sentences
Our Board provides oversight of our risk management process, including risks from cybersecurity threats.
−Removed: Our Board is responsible for monitoring and assessing strategic risk exposure and the mitigation and remediation of cybersecurity incidents, and our executive officers (including our CEO, CFO, and COO) are responsible for the day-to-day management of the material risks we face, including cybersecurity risks.
−Removed: Our Board administers its cybersecurity risk oversight function as a whole, as well as through the Audit and Risk Committee (“ARC”).
−Removed: Our corporate security team informs the Board and ARC of certain cybersecurity risks and threats during quarterly meetings and provide materials shared in connection with such meetings, as well as ad hoc updates when there are material developments or changes that may impact cybersecurity risk to the company.
+Added: Our Board is responsible for monitoring and assessing strategic risk exposure and the mitigation and remediation of cybersecurity incidents, and our executive officers (including our Chief Executive Officer, Chief Financial Officer, and Chief Operating Officer) are responsible for the day-to-day management of the material risks we face, including cybersecurity risks.
+Added: Our Board administers its cybersecurity risk oversight function as a whole, as well as through the Audit Committee (“AC”).
+Added: Our corporate security team informs the Board and AC of certain cybersecurity risks and threats during quarterly meetings and provide materials shared in connection with such meetings, as well as ad hoc updates when there are material developments or changes that may impact cybersecurity risk to the company.
Refer to “Item 10.
−Removed: Directors, Executive Officers and Corporate Governance” section of this Annual Report for additional information regarding the ARC and other committees of the Board as well as the ARC charter.
+Added: Directors, Executive Officers and Corporate Governance” section of this Annual Report for additional information regarding the AC and other committees of the Board as well as the AC charter.
Responsibilities of Management
−Removed: Our corporate security team consists of the Manager of Security Engineering, a Senior Security Engineer, a Senior SRE and a Security Engineering Contractor.
+Added: Our corporate security team consists of the Chief Information Security Officer, the Manager of Security Engineering, a Senior Security Engineer, a Senior SRE, and a Security Engineering Contractor.
The corporate security team is primarily responsible for assessing and managing material risks from cyber security threats, defining and overseeing our corporate security program, reviewing technical designs and vendors for security risks, and managing our security tools and infrastructure.
4 unchanged sentences
Several team members participate in groups that focus on information security such as OWASP, Open Security Summit and other professional organizations and projects.
−Removed: Our Manager of Security Engineering provides frequent briefings to management regarding the Company’s cyber security risks and risk-mitigation efforts, which may include recent incidents and related responses, newly identified risks, changes to the security program, and activities of third parties and vendors, as appropriate.
+Added: Our Chief Information Security Officer provides frequent briefings to management regarding the Company’s cyber security risks and risk-mitigation efforts, which may include recent incidents and related responses, newly identified risks, changes to the security program, and activities of third parties and vendors, as appropriate.
Management provides cybersecurity updates to executive management and the Board through meetings and materials shared in connection with those meetings, as well as ad hoc updates when there are material developments or changes.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.