4 unchanged sentences
Governance of Cybersecurity Risks
−Removed: From a governance perspective, our Audit Committee oversee our cybersecurity program, including the management of risks arising from cybersecurity threats.
−Removed: Our Audit Committee receives quarterly reports from both internal (e.g., management) and external sources (e.g., third-arty consultants), which cover topics that include, but are not limited to, recent cyber devel opments, evolving cyber standards, vulnerability assessments, third-party and independent reviews, the cyber threat environment, technological trends, and other cybersecurity considerations arising with respect to our company and third parties.
−Removed: Our GISO also keeps our executive team and our Audit Committee (if necessary) informed regarding any security incident that meets established reporting thresholds and ongoing updates regarding any such incident until it has been closed out.
+Added: From a governance perspective, our Audit Committee oversees our cybersecurity program, including the management of risks arising from cybersecurity threats.
+Added: Our Audit Committee receives quarterly reports from both internal (e.g., management) and external sources (e.g., third-party consultants), which cover topics that include, but are not limited to, recent cyber devel opments, evolving cyber standards, vulnerability assessments, third-party and independent reviews, the cyber threat environment, technological trends, and other cybersecurity considerations arising with respect to our company and third parties.
+Added: Our GISO and Chief Legal Officer also keep our executive team and our Audit Committee (if necessary) informed regarding any security incident that meets established reporting thresholds and provide ongoing updates regarding any such incident until it has been closed out.
Management of Cybersecurity Risks
4 unchanged sentences
Engagement of Third-Parties
−Removed: Our GISO partners with third-party cybersecurity service and product vendors to provide protection of our networks, information resources, products, services and data for our customers and employees.
+Added: Our GISO partners with third-party cybersecurity service and product vendors to provide protection of our networks, information resources, products, services and data of our customers and employees.
Furthermore, our GISO engages third-party cybersecurity and data protection experts to perform assessments on the efficacy of our cybersecurity program and measures, including cybersecurity maturity assessments, audits and independent reviews of our cybersecurity control environment and operating effectiveness.
2 unchanged sentences
For example, in general, we contractually require our third-party service providers to maintain cybersecurity controls to protect our confidential information, to share information with our company about their information security programs and to inform us of any security incidents on their systems that could impact our operations or confidential information.
−Removed: Although we rely on our third party service providers to implement security programs commensurate with their risk, we cannot ensure in all circumstances that their efforts will be successful.
+Added: rely on our third party service providers to implement security programs commensurate with their risk, we cannot ensure in all circumstances that their efforts will be successful.
Our Senior Leadership Team’s Qualifications
−Removed: Our current Chief Information Security Officer has served in various roles in information technology and information security for over 15 years, including as the Director of Information Security at the Colombian operations of a telecommunications company operating throughout Latin America and as the Head of Information Security in the Colombian operations of a large retail company operating in South America.
+Added: Our Chief Information Security Officer has served in various roles in information technology and information security for over 15 years, including as the Director of Information Security at the Colombian operations of a telecommunications company operating throughout Latin America and as the Head of Information Security in the Colombian operations of a large retail company operating in South America.
Our Chief Information Security Officer holds undergraduate, graduate and master’s degrees in risk management, business administration and information technology, as well as professional certification as a Certified Information Security Manager.
−Removed: Our current Chief Technology Officer has extensive experience in running and managing cyber risks at large U.S.
+Added: Our Chief Information Security Officer reports to our Chief Legal Officer, who has served in that position since December 2017.
+Added: Our Chief Legal Officer manages our cybersecurity function and legal matters affecting our company and risk management within the company.
+Added: Our Chief Legal Officer’s responsibilities also include overseeing legal support for corporate governance, financial reporting, litigation, mergers and acquisitions and commercial contracts, regulatory and general compliance matters at our company and management of our government affairs function.
+Added: In addition, our Chief Technology Officer has extensive experience in running and managing cyber risks at large U.S.
telecommunication companies and, prior to joining our company, had led the cybersecurity practice at a business unit at a large telecommunications company and established cyber risk identification, detection and protection practices for enterprise and government customers.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.