4 unchanged sentences
We have implemented a risk-based, multilayered approach to assessing, identifying, and managing cybersecurity threats and incidents, while also implementing controls and procedures that provide for the prompt escalation of certain cybersecurity incidents.
−Removed: The team devotes significant resources to our cybersecurity risk management, which focuses on developing and implementing strategies and processes to protect the confidentiality, integrity, and availability of our assets and those of our consumers, customers and employees and seeks to continually improve our policies and practices to protect our platforms, adapt to changes in regulations, identify potential and emerging security risks and develop mitigation strategies for those risks.
+Added: The team devotes significant resources to our cybersecurity risk management , which focuses on developing and implementing strategies and processes to protect the confidentiality, integrity, and availability of our assets and those of our consumers, customers and employees and seeks to continually improve our policies and practices to protect our platforms, adapt to changes in regulations, identify potential and emerging security risks such as those due to the increased availability of artificial intelligence and develop mitigation strategies for those risks.
As part of this effort, the team periodically benchmarks our practices against the NIST Cyber Security and Privacy Frameworks, and other good practice control methods, which include updating technology, developing data privacy and security policies and procedures, implementing and assessing the effectiveness of controls, monitoring and routine testing of our information systems, conducting risk assessments of third-party service providers, providing data privacy and cybersecurity awareness training to employees and designing business processes to protect private data and mitigate the risk of cybersecurity incidents.
We periodically conduct tests on our systems to help discover potential vulnerabilities, which enable improved decision-making and prioritization and promote monitoring and reporting across compliance functions.
−Removed: We believe that these
−Removed: actions provide adequate measures of protection against security breaches and generally reduce our cybersecurity risks, and we have not had a material cybersecurity threat or attack to date.
+Added: We believe that these actions provide adequate measures of protection against security breaches and generally reduce our cybersecurity risks, and we have not had a material cybersecurity threat or attack to date.
Our processes also address cybersecurity risks associated with our use of third-party service providers including suppliers, and software and cloud-based service providers.
13 unchanged sentences
Our Board and the Audit Committee are actively engaged in the oversight of our cybersecurity and data privacy program.
−Removed: The Board, at least annually, and the Audit Committee, periodically throughout the year, receive regular reports from our Chief Information Security Officer (“CISO”) and members of the information security team on, among other things, recent developments, the state of the information security program, assessments of risks and threats to our information security systems, information security considerations arising with respect to our peers and third parties, third-party and independent reviews, and processes to maintain and strengthen information security systems.
+Added: The Board, at least annually, and the Audit Committee, periodically throughout the year, receive regular reports from our Chief Information Security Officer (“CISO”) and members of the information security team on, among other things, recent developments, the state of the information security program, assessments of risks and threats to our information security systems, information security considerations arising with respect to our peers and
+Added: third parties, third-party and independent reviews, and processes to maintain and strengthen information security systems.
Under the oversight of the Audit Committee, we engage third-party experts to assess the state of our cybersecurity and data privacy program.
2 unchanged sentences
We have an Executive Cybersecurity Steering Committee that is facilitated by our CISO, which is designed to engage business leadership and employ best practices, including ongoing enhancements to governance, risk and compliance.
+Added: We have adopted governance policies and procedures related to artificial intelligence development, deployment and monitoring.
Our internal audit function also performs independent testing on aspects of the operations of our cybersecurity program and the supporting controls based upon its risk-based internal audit plan and reports the results of these audits in its periodic reports to the Audit Committee.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.