6 unchanged sentences
We invest heavily in technology and third-party support to identify, mitigate, and quickly respond to cybersecurity incidents , and we have maintained a strong focus in consistently reviewing fundamental cybersecurity practices and ensuring we are reviewing emerging threats.
−Removed: To respond to the threat of security breaches and cyberattacks, we maintain a cybersecurity program designed to protect and preserve the confidentiality, integrity and continued availability of all information owned by, or in the care of, LP.
+Added: To respond to the threat of security breaches and cyberattacks, we maintain a cybersecurity program designed to protect and preserve the confidentiality, integrity and continued availability of all information and operational processes owned by, or in the care of, LP.
This program includes mechanisms to monitor and detect unusual network activity, cybersecurity incident response and containment tools, and a response plan that provides controls and procedures for timely and accurate reporting of any material cybersecurity incident.
2 unchanged sentences
We evaluate third-party cybersecurity risk controls through various assessment activities carried out by LP employees and by third-party service providers acting on our behalf.
−Removed: We engage an independent third party to conduct an annual Security Program Assessment under the Capability Maturity Model Integration framework.
+Added: We engage independent third parties to conduct, on an annual basis, either a Security Program Assessment under the Capability Maturity Model Integration (CMMI) framework or the National Institute of Standards and Technology (NIST) framework, or targeted penetration testing combined with security controls assessments.
For incident alerts and response, we outsource around-the-clock coverage to a third-party managed service provider who provides timely alerting and notification of potential cybersecurity issues.
−Removed: In 2023, we also engaged a specialized third-party assessor to perform an operational technology security assessment for a subset of our manufacturing facilities.
We continually work with third-party experts to advise on new threats and cybersecurity strategy best practices for specific capabilities.
3 unchanged sentences
Our cybersecurity program is managed by our Information Security Officer (ISO) .
−Removed: Our ISO has over six years of cybersecurity experience working in publicly traded companies, with expertise leading risk remediation efforts in vulnerability management, network security, security awareness, threat monitoring, data security and cloud security.
+Added: Our ISO has over eight years of cybersecurity experience working in publicly traded companies, with expertise leading risk remediation efforts in vulnerability management, network security, security awareness, threat monitoring, data security and cloud security.
To more effectively share information and gain consensus regarding cybersecurity initiatives and prevention policies, the Company has in place an Enterprise Risk Management Committee consisting of various members of LP senior leadership including the Chief Legal Counsel and Chief Financial Officer.
The Enterprise Risk Management Committee is chaired by our Chief Tax Officer.
−Removed: The ISO, along with her team, is responsible for leading an enterprise-wide information security strategy, including policy, standards, architecture, processes, and security technology.
+Added: The ISO, along with the cybersecurity team, is responsible for leading an enterprise-wide information security strategy, including policy, standards, architecture, processes, and security technology.
The Enterprise Risk Management Committee (i) meets quarterly and as-needed to review and discuss the Company’s risks, including cybersecurity threats, incident responses, technology, the status of projects to strengthen the Company’s information security systems, assessments of the Company’s cybersecurity program and the emerging threat landscape and (ii) reports risks related to any material cybersecurity incidents, as needed, to the Board of Directors and the Finance and Audit Committee (FAC) of the Board of Directors.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.