10 unchanged sentences
The Company’s incident response and remediation plans are further supported by ongoing security monitoring services as well as a dedicated management team focused on business continuity to help support operations and mitigate disruptions should a breach, unauthorized access or other disruption event occur.
−Removed: In addition, the Company has established a zero trust network access roadmap that includes key security controls designed to help protect Matson employees and contractors with access to Matson systems against phishing and brute force password attacks.
+Added: In addition, the Company has implemented a zero trust network access framework that includes key security controls designed to help protect Matson employees and contractors with access to Matson systems against phishing and brute force password attacks.
The risk management process occurs throughout the organization, but is facilitated through a risk management steering committee comprised of senior management whose members meet regularly to identify and address specific significant risks.
12 unchanged sentences
In furtherance of this aim, the Company conducts training annually for employees that addresses cyber and information security, and holds additional training typically at least three times per year for specific topics such as data and email security.
−Removed: Furthermore, Matson requires enhanced training for employees with access to particularly sensitive information.
+Added: Furthermore, Matson requires enhanced training for employees with access to particularly sensitive information or critical systems.
The Company also has specific escalation processes and resources in place for employees to raise a concern should they notice anything suspicious.
2 unchanged sentences
● NIST 800-171
+Added: ● Cybersecurity Maturity Model Certification (“CMMC”) 2.0
● NIST 800-82
1 unchanged sentence
● IMO MSC-FAL.1/Circ.3/Rev.3
+Added: ● United States Coast Guard – Final Rule:
+Added: Cybersecurity in the Marine Transportation System (“MTS”)
● BIMCO’s Guidelines for Cyber Security Onboard Ships
16 unchanged sentences
Senior leaders, including Matson’s Chief Information Officer, review the Company’s cybersecurity program with the Board at least annually, and the Chief Information Officer meets with the Audit Committee at least twice per year.
−Removed: Matson’s information security efforts are led by its Chief Information Officer , who has over 25 years of experience in enterprise software development, infrastructure and management, including over 18 years with Matson and 7 years at Charles Schwab as Senior Manager of Middleware Security, and the Chief Information Security Officer , who is a Certified Information Systems Security Professional, Certified Information Systems Auditor, and is AWS Certified.
+Added: Matson’s information security efforts are led by its Chief Information Officer , who has over 25 years of experience in enterprise software development, infrastructure and management, and its Chief Information Security Officer , who is a Certified Information Systems Security Professional, Certified Information Systems Auditor, and is AWS Certified.
The Chief Information Officer and the Chief Information Security Officer provide regular briefings to the Chief Executive Officer, the Chief Financial Officer, the Board, and the Audit Committee.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.