3 unchanged sentences
The Company, under the oversight of the Audit Committee of its Board of Directors, has implemented and maintains a cybersecurity risk management program that includes processes for the systematic identification, assessment and treatment (through mitigation, transfer, avoidance and/or acceptance) of cybersecurity risks.
−Removed: This program extends to third-party vendors and the various properties under the Company’s management, including corporate and commercial properties, through establishing vendor risk requirements and conducting vendor risk assessments.
+Added: This program extends to third-party vendors
+Added: and the various properties under the Company’s management, including corporate and commercial properties, through establishing vendor risk requirements and conducting vendor risk assessments.
This risk management program addresses, but is not limited to, risks identified by external auditors and assessors, internal auditors and assessors, threat intelligence providers, internal stakeholders, vulnerability management programs and security management programs.
−Removed: An internal audit team at the Company manages and maintains remediation strategies for identified risks, and reports on them regularly to senior leadership.
+Added: An internal audit team at the Company manages and maintains remediation strategies for identified risks for the Company and its vendors, and reports on them regularly to senior leadership.
As part of the Company’s cyber risk management program, the Company has engaged external independent assessors to conduct cyber risk assessments, evaluate cyber risk management controls, and report both findings and recommendations to management.
7 unchanged sentences
The SVP-IT meets with the Chief Financial Officer and Chief Legal Officer quarterly to monitor and review the outcomes of the Company’s cybersecurity risk management processes and to discuss and decide matters related to cybersecurity risk treatment strategy (including mitigations).
−Removed: The Company also formed the Business Continuity Plan ("BCP") and Cyber Security Risk Committee (the “Security Committee”), which oversees the prioritization and escalation of risks from cybersecurity threats to senior leadership, is chaired by the SVP-IT and the Executive Vice President of Portfolio Operations and People.
+Added: The Company also formed the Business Continuity Plan ("BCP") and Cyber Security Risk Committee (the “Security Committee”), which oversees the prioritization and escalation of risks from cybersecurity threats to senior leadership, is chaired by the SVP-IT and the Executive Vice President of Enterprise Operations.
The Security Committee reports to the Chief Financial Officer and Chief Legal Officer, and the committee’s members include senior company leadership responsible for asset management, risk management, property management, marketing, and business development.
3 unchanged sentences
As reflected in the Audit Committee charter, the committee is responsible for reviewing information technology, cybersecurity and other data protection strategies and plans, as well as assessing incident response protocols.
−Removed: The Security Committee provides quarterly reports to the Audit Committee and the SVP-IT attends board meetings yearly, or more frequently as appropriate, to inform the Company’s Board of Directors on cybersecurity risks.
+Added: The Security Committee provides quarterly reports to the Board of Directors and the SVP-IT attends board meetings yearly, or more frequently as appropriate, to inform the Company’s Board of Directors on cybersecurity risks.
Additionally, the Company is subject to the requirements of the Sarbanes-Oxley Act of 2002 and information technology general controls are an important part of the Company's internal control over financial reporting and are subject to controls testing.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.