4 unchanged sentences
Our corporate cybersecurity risk management program provides a framework for handling cybersecurity threats and incidents, including threats and incidents associated with the use of services provided by third-party vendors and service providers , and facilitating coordination across different business units of the Company.
−Removed: Our corporate cybersecurity risk management program is based on and audited against industry standards, including ISO 27001 for Information Security Management Systems (ISMS) and the automotive industry’s Trusted Information Security Assessment Exchange standard.
+Added: Our corporate cybersecurity risk management program is based on and audited against industry standards, including ISO 27001 for Information Security Management Systems (ISMS) and the automotive industry’s Trusted Information Security Assessment Exchange standard (TISAX).
Our corporate cybersecurity team is responsible for operating our cybersecurity risk management program.
13 unchanged sentences
Our CISO has served in that position since 2019 and has over 25 years of managerial and professional cybersecurity expertise.
−Removed: He has held the role of CISO and other senior management positions with NDS Services, Cisco Systems, Inc.
−Removed: and Deloitte and has also served as cybersecurity consultant for companies in multiple global industries.
−Removed: Our COO has extensive experience in project management and cybersecurity, including from past roles with Verint Systems Inc.
−Removed: and Cisco Systems, Inc.
−Removed: as well as the establishment and management of the Company’s cybersecurity team prior to our CISO joining the Company.
+Added: He has held the role of CISO and other senior management positions with NDS, Cisco and Deloitte and has also served as cybersecurity consultant for companies in multiple global industries.
+Added: Our COO has extensive experience in project management and cybersecurity, including from past roles with Verint - Systems and Cisco Systems as well as the establishment and management of the Company’s cybersecurity team prior to our CISO joining the Company.
Management is responsible for identifying, considering and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential cybersecurity risk exposures are monitored, putting in place appropriate mitigation measures and maintaining cybersecurity programs.
1 unchanged sentence
The COO in turn periodically reports on such matters to the Chief Executive Officer and other members of management.
−Removed: As part of our continued investment in developing our overall enterprise risk management program, the COO and other members of management make updates to the full board of directors, and going forward beginning in 2024, will also provide updates to the audit committee of our board of directors (the “Audit Committee”), on the Company’s cybersecurity programs, material cybersecurity risks and mitigation strategies.
−Removed: In addition to such updates, and as part of our incident response processes, our COO is also responsible for informing the Audit Committee of material cybersecurity threats and incidents, based on management’s assessment of risk.
+Added: The COO and CISO provide updates to the audit committee of our board of directors (the “Audit Committee”) on the Company’s cybersecurity programs, material cybersecurity risks and mitigation strategies.
+Added: In addition to such regular updates, and as part of our incident response processes, our COO is also responsible for informing the Audit Committee of material cybersecurity threats and incidents, based on management’s assessment of risk.
Our board of directors has overall oversight responsibility for our risk management, and delegates cybersecurity risk management oversight to the Audit Committee.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.