3 unchanged sentences
We manage cybersecurity threats as part of our oversight, evaluation, and mitigation of enterprise-level risks.
−Removed: We have based our cybersecurity program on industry frameworks with the goal of building enterprise resilience against an evolving landscape of cybersecurity threats and to respond to cybersecurity threats as they materialize.
−Removed: Our program includes monitoring, identification, assessment, and management components, as well as information and escalation components designed to inform management and the board of directors of prospective risks and developments.
+Added: We have based our cybersecurity program on industry frameworks, including, among others, the U.S.
+Added: National Institute of Standards and Technology Cybersecurity Framework, with the goal of building enterprise resilience against an evolving landscape of cybersecurity threats and responding to cybersecurity threats as they materialize.
+Added: Our program includes monitoring, identification, assessment, and management components, as well as information sharing and escalation components designed to inform management and the board of directors of prospective risks and developments.
Our information security program encompasses functions dedicated to both proactive and reactive management of cybersecurity threats.
5 unchanged sentences
As examples, we generally review current and prospective third-party service providers for unacceptable cybersecurity risks, negotiate contractual provisions that require the establishment of third-party cybersecurity controls, and deploy communications security measures to protect third-party communications.
+Added: For companies we acquire, the integration process includes plans for alignment with relevant information security policies and procedures and timelines for implementation.
We assess cybersecurity contingencies within our overall business continuity risk management planning process.
3 unchanged sentences
Roles and escalation paths range from within the Information Security team up to the Executive Committee, and the board of directors and its committees, as appropriate.
−Removed: We describe risks faced by us from identified cybersecurity threats in Item 1A, "Risk Factors—Risks Related to Our Operations— Failure, inadequacy, breach of, or unauthorized access to, our IT systems or those of our third-party service providers, unauthorized access to our confidential information, or violations of data protection laws, could each result in material harm to our business and reputation", "Risk Factors—Risks Related to Our Operations—Manufacturing, quality, or supply chain difficulties, disruptions, or shortages could lead to product supply problems" and "Risk Factors—Risks Related to Our Operations—Reliance on third-party relationships and outsourcing arrangements could adversely affect our business."
+Added: We describe risks faced by us from identified cybersecurity threats in Item 1A, "Risk Factors—Risks Related to Our Operations—Failure, inadequacy, breach of, or unauthorized access to, our IT systems or those of our third-party service providers, unauthorized access to our confidential information, or violations of data protection laws, could each result in material harm to our business and reputation", "Risk Factors—Risks Related to Our Operations—Manufacturing, quality, or supply chain difficulties, disruptions, or shortages could lead to product supply problems", "Risk Factors—Risks Related to Our Operations—Reliance on third-party relationships and outsourcing arrangements could adversely affect our business", and "Risk Factors—Risks Related to Our Operations—Our use of artificial intelligence (AI) or other emerging technologies could adversely impact our business and financial results."
Management, under the supervision of our Chief Information Security Officer (CISO) , is directly responsible for assessing and managing cybersecurity risks and otherwise implementing our cybersecurity program, which includes our Incident Response Playbook.
2 unchanged sentences
Our CISO and CIDO have significant experience managing global cybersecurity threats across the pharmaceutical, technology, entertainment, and defense industries.
−Removed: In addition to providing regular updates to the CIDO and his staff, the CISO is a member of our Executive Information Security Governance function (EISG), which meets regularly and is also composed of executive and senior leadership from a variety of functions, including information security, legal, finance, audit, and ethics and compliance to assess and manage cybersecurity developments and risks and our internal programs.
+Added: In addition to providing regular updates to the CIDO and his staff, the CISO is a member of our Executive Information Security Governance function (EISG), which meets regularly and is composed of executive and senior leadership from a variety of functions, including information security, legal, finance, audit, and ethics and compliance to assess and manage cybersecurity developments and risks and our internal programs.
Each of the CIDO, the CISO and the EISG may call upon business and legal stakeholders across our company to manage cybersecurity threats and incidents.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.