11 unchanged sentences
We evaluate third-party cybersecurity risk controls through various assessment activities carried out by LP employees and by third-party service providers acting on our behalf.
−Removed: We engage an independent third party to conduct a biennial Security Program Assessment under the National Institute of Standards and Technology Cybersecurity framework.
+Added: We engage an independent third party to conduct an annual Security Program Assessment under the Capability Maturity Model Integration framework.
For incident alerts and response, we outsource around-the-clock coverage to a third-party managed service provider who provides timely alerting and notification of potential cybersecurity issues.
5 unchanged sentences
Our cybersecurity program is managed by our Information Security Officer (ISO) .
−Removed: Our ISO has over five years of cybersecurity experience working in publicly traded companies, with expertise leading risk remediation efforts in vulnerability management, network security, security awareness, threat monitoring, data security and cloud security.
−Removed: To more effectively share information and gain consensus regarding cybersecurity initiatives and prevention policies, the Company has in place a Cyber Council consisting of various members of LP senior leadership and the Chief Information Officer.
−Removed: The Cyber Council is chaired by our ISO.
+Added: Our ISO has over six years of cybersecurity experience working in publicly traded companies, with expertise leading risk remediation efforts in vulnerability management, network security, security awareness, threat monitoring, data security and cloud security.
+Added: To more effectively share information and gain consensus regarding cybersecurity initiatives and prevention policies, the Company has in place an Enterprise Risk Management Committee consisting of various members of LP senior leadership including the Chief Legal Counsel and Chief Financial Officer.
+Added: The Enterprise Risk Management Committee is chaired by our Chief Tax Officer.
The ISO, along with her team, is responsible for leading an enterprise-wide information security strategy, including policy, standards, architecture, processes, and security technology.
−Removed: The Cyber Council (i) meets semi-annually to review and discuss the Company’s cybersecurity risks and threats, incident responses, technology, the status of projects to strengthen the Company’s information security systems, assessments of the Company’s cybersecurity program and the emerging threat landscape and (ii) reports risks related to any material cybersecurity incidents, as needed, to the Board of Directors and the Finance and Audit Committee (FAC) of the Board of Directors.
+Added: The Enterprise Risk Management Committee (i) meets quarterly and as-needed to review and discuss the Company’s risks, including cybersecurity threats, incident responses, technology, the status of projects to strengthen the Company’s information security systems, assessments of the Company’s cybersecurity program and the emerging threat landscape and (ii) reports risks related to any material cybersecurity incidents, as needed, to the Board of Directors and the Finance and Audit Committee (FAC) of the Board of Directors.
Board Responsibilities
2 unchanged sentences
The ISO provides the FAC with an annual presentation on our cybersecurity program, emerging threats, and the state of LP’s cybersecurity maturity.
−Removed: In addition, the ISO provides updates to the FAC no less often than quarterly with respect to materials regarding the cybersecurity program.
+Added: In addition, the ISO provides updates to the FAC no less often than annually with respect to additional information regarding the cybersecurity program.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.