28 unchanged sentences
Those sections of Item 1A should be read in conjunction with this Item 1C.
−Removed: The Chief Information Officer ("CIO") is the management position with primary oversight responsibility for the team responsible for the development, operation, and maintenance of our information security program.
−Removed: Pursuant to the Company’s written IRP, the CIO is a member of the executive incident response team and severity classifications in the IRP are used to escalate matters to the executive incident response team.
−Removed: The CIO has more than 20 years of comprehensive IT experience across a breadth of technologies.
−Removed: The CIO is also a member of the Company’s executive leadership team and meets regularly with the CEO, CFO, and other members of the executive leadership team .
+Added: The Chief Information Officer (“CIO”) has management oversight responsibility for the Company’s information security program and cybersecurity strategy.
+Added: The Company has appointed a Chief Information Security Officer (“CISO”), who reports directly to the CIO and is responsible for the development, operation, and maintenance of the Company’s information security program, including implementation of security policies, incident response coordination, risk management activities, and ongoing monitoring of the Company’s information technology environment.
+Added: Pursuant to the Company’s written Incident Response Plan (“IRP”), both the CIO and CISO are members of the executive incident response team, and severity classifications in the IRP are used to escalate matters to the executive incident response team.
+Added: The CIO has more than 20 years
+Added: of comprehensive IT experience across a breadth of technologies, and the CISO brings significant experience in cybersecurity operations, risk management, and information security practices.
+Added: The CIO is also a member of the Company’s executive leadership team and meets regularly with the CEO, CFO, and other members of executive management regarding cybersecurity risks, strategy, and incidents.
The CIO reports directly to the Board , at least twice a year, on cybersecurity risks and strategy and attends Board meetings to be available to discuss cybersecurity matters with the Board.
+Added: The CISO also supports these reporting and governance activities, as appropriate.
Oversight of the information security program at the Board level sits with the Audit Committee.
−Removed: The CIO reports to the Audit Committee on risks and internal controls related to cybersecurity and information technology and systems at least annually and attends quarterly Committee meetings to be available to discuss such matters with the Audit Committee.
+Added: The CIO and CISO report to the Audit Committee on risks and internal controls related to cybersecurity and information technology and systems at least annually and attends quarterly Committee meetings to be available to discuss such matters with the Audit Committee.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.