12 unchanged sentences
We also maintain enterprise-wide processes to oversee and identify risks from cybersecurity threats associated with our use of third-party service providers.
−Removed: As examples, we generally review current and prospective third-party service providers for unacceptable cybersecurity risks, negotiate contractual provisions that require the establishment of third-party cybersecurity controls, and deploy communications security measures to protect third-party communications.
−Removed: For companies we acquire, the integration process includes plans for alignment with relevant information security policies and procedures and timelines for implementation.
+Added: As examples, we generally review current and prospective third-party service providers for unacceptable cybersecurity risks, negotiate contractual provisions that require the establishment of third-party cybersecurity controls, and deploy security measures to protect third-party communications.
+Added: For companies we acquire, the integration process includes plans for alignment with relevant information security policies and procedures.
We assess cybersecurity contingencies within our overall business continuity risk management planning process.
3 unchanged sentences
Roles and escalation paths range from within the Information Security team up to the Executive Committee, and the board of directors and its committees, as appropriate.
−Removed: We describe risks faced by us from identified cybersecurity threats in Item 1A, "Risk Factors—Risks Related to Our Operations—Failure, inadequacy, breach of, or unauthorized access to, our IT systems or those of our third-party service providers, unauthorized access to our confidential information, or violations of data protection laws, could each result in material harm to our business and reputation", "Risk Factors—Risks Related to Our Operations—Manufacturing, quality, or supply chain difficulties, disruptions, or shortages could lead to product supply problems", "Risk Factors—Risks Related to Our Operations—Reliance on third-party relationships and outsourcing arrangements could adversely affect our business", and "Risk Factors—Risks Related to Our Operations—Our use of artificial intelligence (AI) or other emerging technologies could adversely impact our business and financial results."
+Added: We describe certain risks faced by us from identified cybersecurity threats in Item 1A, "Risk Factors—Risks Related to Our Operations—Failure, inadequacy, breach of, or unauthorized access to, our IT systems or those of our third-party service providers, unauthorized access to our confidential information, or violations of data protection laws, could result in material harm to our business and reputation", "Risk Factors—Risks Related to Our Operations—Manufacturing, quality, or supply chain difficulties, disruptions, or shortages could lead to product supply problems or other negative outcomes", "Risk Factors—Risks Related to Our Operations—Reliance on third-party relationships and outsourcing arrangements could adversely affect our business", and "Risk Factors—Risks Related to Our Operations—Our use of artificial intelligence (AI) or other emerging technologies could adversely impact us."
Management, under the supervision of our Chief Information Security Officer (CISO) , is directly responsible for assessing and managing cybersecurity risks and otherwise implementing our cybersecurity program, which includes our Incident Response Playbook.
4 unchanged sentences
Each of the CIDO, the CISO and the EISG may call upon business and legal stakeholders across our company to manage cybersecurity threats and incidents.
−Removed: The audit committee of our board of directors is responsible for oversight of the company's programs, policies, procedures, and risk management activities related to information security and data protection.
−Removed: The audit committee meets regularly with our CIDO and CISO to discuss threats, risks, and ongoing efforts to enhance cyber resiliency, as well as changes to the broader cybersecurity landscape.
+Added: Our board of directors monitors cybersecurity risks and regularly participates in presentations on cybersecurity and information technology.
+Added: The audit committee of our board of directors is responsible for oversight of our programs, policies, procedures, and risk management activities related to information security, cybersecurity and data protection.
+Added: The audit committee meets regularly with our CIDO, CISO, and Chief Privacy Officer to discuss threats, risks, and ongoing efforts to enhance cyber resiliency, as well as changes to the broader cybersecurity landscape.
In addition, the ethics and compliance committee supports the audit committee and board in oversight of legal and regulatory compliance.
−Removed: Our board of directors also regularly participates in presentations on cybersecurity and information technology.
In addition to regular presentations, management promptly updates our board of directors regarding significant threats and incidents as they arise.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.