2 unchanged sentences
The Company’s Chief Information Officer (“CIO”) leads our Information Security Committee (a taskforce comprised of senior representatives from primary corporate functions, mortgage and title operations, IT infrastructure, IT security, and external security consultants) , which is responsible for developing, updating, implementing and maintaining our cybersecurity strategy, policy (which leverages the NIST CSF framework), standards, architecture, and processes.
−Removed: The CIO provides annual reports to our Board of Directors, and periodic reports to our Chief Executive Office (“CEO”), Chief Financial Officer (“CFO”) and Chief Accounting Officer (“CAO”), and other members of senior management, regarding existing and emerging cybersecurity risks and threats, the status of projects intended to strengthen our information security systems, and assessments of our information security program.
+Added: The Company has integrated cyber security into its annual risk assessment process.
+Added: This process identifies critical assets and assesses those assets for potential threats and vulnerabilities.
+Added: Risks are prioritized based on their impact and likelihood.
+Added: Controls are assessed to ensure the Company’s controls are appropriate to mitigate risks.
+Added: It also allows us to identify any gaps that we need to focus on.
+Added: These gaps are typically part of the Information Security Committees risk register.
+Added: The Information Security Committee meets quarterly and continuously monitors and re-evaluates risks through this risk register, which was initially developed using the NIST CSF framework.
+Added: The CIO provides annual reports to our Board of Directors, and periodic reports to our Chief Executive Officer (“CEO”), Chief Financial Officer (“CFO”) and Chief Accounting Officer (“CAO”), and other members of senior management, regarding existing and emerging cybersecurity risks and threats, the status of projects intended to strengthen our information security systems, and assessments of our information security program.
Members of senior management are notified by our Information Security Committee if any cybersecurity incident leads to a breach or loss of any data.
17 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.