3 unchanged sentences
Logitech’s security capability is designed to protect the confidentiality, integrity, availability and accessibility of Logitech’s information, digital assets, products and services.
−Removed: Our security capability includes:
−Removed: (i) cybersecurity, which protects information and digital assets used at Logitech to conduct business and (ii) product security, which protects Logitech products and services provided to our customers.
Risk Management and Strategy
We have established a Security Governance Framework that defines roles and responsibilities, so that security is taken into account at all levels and in every department or function of the Company.
−Removed: Identifying and assessing cybersecurity risk is integrated into our enterprise risk management.
+Added: Our framework provides guidance for the organization, governance and implementation of security across the company.
+Added: Logitech and its infrastructure have been certified for compliance with ISO 27001, an international standard for information security management.
+Added: Identifying and assessing cybersecurity risks is integrated into our enterprise risk management.
+Added: As part of our risk management program, we continuously assess risks from third parties, including vendors, suppliers, and other business partners associated with our use of third-party service providers.
We have implemented incident response and breach management processes that include the following steps:
1 unchanged sentence
We also conduct tabletop exercises to, among other things, align activities and expectations in connection with our incident response processes, discuss strategic questions, and review third party recommendations.
−Removed: Our security framework provides guidance for the organization, governance and implementation of security across the company.
−Removed: Logitech and its infrastructure have been certified for compliance with ISO 27001, an international standard for information security management.
−Removed: As part of our risk management program, we continuously assess risks from third parties, including vendors, suppliers, and other business partners associated with our use of third-party service providers.
We have not previously experienced a cybersecurity event that was determined to be material, and our business strategy, results of operations and financial condition have not been materially affected by risks from cybersecurity threats.
For additional information regarding risks from cybersecurity threats, please refer to Item 1A "Risk Factors" in this Annual Report on Form 10-K.
+Added: Logitech International S.A.
+Added: | Fiscal 2025 Form 10-K | 32
Board of Directors and Board Committees Oversight of Risks from Cybersecurity Threats
5 unchanged sentences
Finally, the Board has formed a Cyber Crisis Subcommittee tasked with overseeing any future significant cybersecurity crisis.
−Removed: Logitech International S.A.
−Removed: | Fiscal 2024 Form 10-K | 32
Management’s Role in Assessing and Managing Material Risks from Cybersecurity Threats
−Removed: Our Cybersecurity Team is tasked, among other things, with evaluating, reporting and advising about cybersecurity risks, defining and leading the enterprise cybersecurity program to protect Logitech business against cybersecurity threats, maintaining and updating the cybersecurity framework, monitoring the level of compliance with the cybersecurity framework across Logitech digital assets and services, providing enterprise-wide cybersecurity services, defining cybersecurity standards and advising on secure architectures, performing assessments and due diligence checks internally and with business partners, providing cybersecurity guidance for digital projects, creating and deploying cybersecurity training programs, managing cybersecurity incidents and breaches, and monitoring cybersecurity threats.
−Removed: The Cybersecurity Team, which is part of the IT organization, is led by the CISO, who has 20 years of cybersecurity experience across different industries.
−Removed: The Cybersecurity Team leads the enterprise cybersecurity strategy and roadmap, which applies to all information and digital assets, used at Logitech to conduct business.
−Removed: Our cybersecurity is managed based on industry-leading standards such as ISO 27001, National Institute of Standards and Technology (NIST) and Center for Internet Security (CIS).
−Removed: Our Product Security Team is responsible for the development of product security policies and standards for the Company, including supporting product security threat identification, supporting product security risk assessment, building and maintaining security policies, standards and guidelines, performing internal audits against the product security policies and standards, performing product security architecture analysis and reviews, raising product security awareness across the Company, monitoring product security through the product development lifecycle, and managing vulnerabilities (pre- and post-production).
−Removed: The Head of Product Security, who reports to our Head of Software, is accountable for the release or deployment approval of a product based upon the review of internal and external validation (functionality, performance, security) reports.
−Removed: Our Head of Software has more than 20 years of experience leading software teams, including over a decade in the cybersecurity industry.
−Removed: We assess our product security programs against the Open Worldwide Application Security Project (OWASP) Application Security Verification Standard (ASVS) and the Software Assurance Maturity Model (SAMM).
−Removed: Our CISO and the Head of Software regularly report on cybersecurity and product security matters, respectively, to the Audit Committee and/or the Technology and Innovation Committee and the Board of Directors.
+Added: Our Security Team is responsible for evaluating, reporting and advising about security threats and risks, defining and leading the enterprise security program to protect Logitech business against security threats, maintaining and updating the security framework, monitoring the level of compliance with the security framework across Logitech digital assets, products and services, providing enterprise-wide security services, defining security policies, standards and guidelines, advising on secure architectures, performing assessments and due diligence checks internally and with business partners, providing security guidance for digital projects, creating and deploying security training programs, managing security incidents and breaches, and conducting threat intelligence and managing vulnerabilities.
+Added: Our Security Team also monitors security through the entire software and product development lifecycle.
+Added: The Head of Application and Product Security is accountable for the release or deployment approval of a product based upon the review of internal and external validation (functionality, performance, security) reports.
+Added: The Security Team, which is part of the Digital Office organization, is led by the CISO , who has 20 years of security experience across different industries.
+Added: The CISO reports to our Head of Digital Office, who has more than 20 years of experience leading software and infrastructure teams, including over a decade in the cybersecurity industry.
+Added: Our security is managed based on industry-leading standards such as ISO 27001, National Institute of Standards and Technology (NIST), Center for Internet Security (CIS), Open Worldwide Application Security Project (OWASP) Application Security Verification Standard (ASVS) and the Software Assurance Maturity Model (SAMM).
+Added: Our CISO and the Head of Digital Office regularly report on cybersecurity to the Audit Committee and/or the Technology and Innovation Committee and the Board of Directors .
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.