3 unchanged sentences
The Company has integrated cyber security into its annual risk assessment process.
−Removed: This process identifies critical assets and assesses those assets for potential threats and vulnerabilities.
−Removed: Risks are prioritized based on their impact and likelihood.
−Removed: Controls are assessed to ensure the Company’s controls are appropriate to mitigate risks.
−Removed: It also allows us to identify any gaps that we need to focus on.
−Removed: These gaps are typically part of the Information Security Committees risk register.
−Removed: The Information Security Committee meets quarterly and continuously monitors and re-evaluates risks through this risk register, which was initially developed using the NIST CSF framework.
+Added: This process identifies critical assets and assesses those assets for potential threats and vulnerabilities, prioritizes risks based on their impact and likelihood, assesses controls to ensure they appropriately mitigate risks and identifies gaps that require additional attention.
+Added: Gaps identified during this process are typically included in the Information Security Committee’s risk register.
+Added: The Information Security Committee meets quarterly and continuously monitors and re-evaluates risks through its risk register, which was initially developed using the NIST CSF framework.
The CIO provides annual reports to our Board of Directors, and periodic reports to our Chief Executive Officer (“CEO”), Chief Financial Officer (“CFO”) and Chief Accounting Officer (“CAO”), and other members of senior management, regarding existing and emerging cybersecurity risks and threats, the status of projects intended to strengthen our information security systems, and assessments of our information security program.
−Removed: Members of senior management are notified by our Information Security Committee if any cybersecurity incident leads to a breach or loss of any data.
+Added: Our Information Security Committee notifies m embers of senior management if any cybersecurity incident leads to a breach or loss of any data.
These members of senior management are responsible for promptly determining if such an incident is material and notifying our CEO, CFO and our Board of Directors of the material incident and the impact that the incident has had, and is expected to have, on the Company’s reputation, results of operations, financial condition, and business strategy.
16 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.