5 unchanged sentences
We, in conjunction with our Manager and its affiliates, have adopted processes designed to identify, assess and manage material risks from cybersecurity threats.
−Removed: These processes include assessments of internal and external threats to the confidentiality, integrity and availability of the Company’s data and systems along with other material risks to its operations.
+Added: These processes include risk assessments of internal and external threats to the confidentiality, integrity and availability of the Company’s data and systems along with other material risks to its operations.
These risk assessments inform our cybersecurity program and the continued development of a layered set of controls aimed at preventing, detecting, and responding to threats.
TPG’s administrative, organizational, technical and physical security controls include, but are not limited to, policies and procedures, system hardening vulnerability scanning, and patching, employee training and awareness, third-party risk management processes, backup and recovery processes, access controls, data encryption in transit and at rest, network perimeter controls, and identity verification.
+Added: When we engage service providers who will have access to sensitive data or TPG's systems and facilities, TPG's cybersecurity team assesses each service provider’s administrative and technical security controls.
+Added: In addition, as appropriate, the Company seeks to include provisions in its service provider agreements that address its and TPG's requirements as well as industry best practices related to data and cybersecurity, as well as the rights of the Company and TPG to assess, monitor, audit and test such service providers’ cybersecurity programs and practices.
TPG also has policies and controls in place designed to detect and respond to cybersecurity events, including an incident response plan, an incident response team with dedicated roles and responsibilities for assessing and responding to a cybersecurity event, system logging and ongoing monitoring, and periodic training exercises simulating cybersecurity events that are designed to raise awareness and test the team’s response readiness capabilities.
13 unchanged sentences
In addition, the Audit Committee of our Board of Directors (the “Audit Committee”) oversees the management of systemic risks, including cybersecurity, in accordance with its charter.
−Removed: The Audit Committee engages in regular
−Removed: discussions with management regarding the Company’s significant financial risk exposures and the measures implemented to monitor and control these risks.
+Added: The Audit Committee engages in regular discussions with management regarding the Company’s significant financial risk exposures and the measures implemented to monitor and control these risks.
Our Board of Directors, including the Audit Committee, is briefed on our Manager’s information security program and cybersecurity risks at least once each year and as needed in connection with any potentially material cybersecurity incidents.
−Removed: The Chief Information Security Officer reports at least annually to our Board of Directors , including the Audit Committee, and such report may address overall assessment of the Company’s compliance with this and other cybersecurity policies, including topics such as risk assessment, risk management and control decisions, service provider arrangements, test results, security incidents and responses, and recommendations for changes and updates to policies and procedures.
+Added: The Chief Information Security Officer ("CISO") reports at least annually to our Board of Directors , including the Audit Committee, and such report may address overall assessment of the Company’s compliance with this and other cybersecurity policies, including topics such as risk assessment, risk management and control decisions, service provider arrangements, test results, security incidents and responses, and recommendations for changes and updates to policies and procedures.
As an externally managed company, we rely on our Manager and its affiliates’ information systems in connection with our day-to-day operations.
3 unchanged sentences
TPG has also established an Operational Risk Committee (“ORC”) which is responsible for applying the policy decisions of the ERC.
−Removed: Operational responsibility for ensuring the adequacy and effectiveness of our Manager's risk management, control and governance processes is assigned to TPG’s Chief Information Security Officer ("CISO"), who periodically reports, among other things, potentially material cybersecurity incidents to the ORC and reports to the ERC at least annually.
+Added: Operational responsibility for ensuring the adequacy and effectiveness of our Manager's risk management, control and governance processes is assigned to TPG’s CISO, who periodically reports, among other things, potentially material cybersecurity incidents to the ORC and reports to the ERC at least annually.
TPG's cybersecurity team also regularly coordinates with other key stakeholders within the organization, including compliance, human resources, internal audit and legal.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.