8 unchanged sentences
These governance processes apply across the enterprise risk management program to other legal, compliance, strategic, operational and financial risk areas, ensuring that cybersecurity risks are managed effectively and are in line with the organization's risk tolerance and business objectives.
−Removed: Our cyber risk program leverages internationally recognized standards as appropriate.
+Added: Our security program generally incorporates the guidelines of the widely utilized National Institute of Standards and Technology Cybersecurity Framework, though this does not imply we meet any particular technical standards, specifications or requirements.
+Added: As part of our enterprise-wide risk management strategy and commitment to continuous improvement, we are
+Added: actively pursuing ISO/IEC 27001 certification, the internationally recognized standard for information security management systems.
+Added: We have initiated the formal implementation process, including a comprehensive gap assessment and roadmap development.
+Added: Progress toward certification is regularly reviewed by the IT Steering Committee and reported to the Board of Directors.
All employees participate in multiple information security training programs.
18 unchanged sentences
Our Director maintains the following internationally recognized certifications:
−Removed: Global Information Assurance Certification ("GIAC") Security Essentials, GIAC Certified Enterprise Defender, GIAC Certified Incident Handler Certification, GIAC Certified Windows Security Administrator, and GIAC Critical Controls Certification.
+Added: Global Information Assurance Certification ("GIAC"), GIAC Certified Enterprise Defender, GIAC Certified Incident Handler Certification, GIAC Certified Windows Security Administrator, and GIAC Critical Controls Certification.
Our Director reports to our Vice President of Information Technology, who receives continuous updates regarding the prevention, detection, mitigation and remediation of cybersecurity incidents.
Our Vice President of Information Technology has over 20 years of experience in developing and executing strategic initiatives to drive organizational growth and innovation, with responsibilities for IT governance, technology strategy development, and cybersecurity.
−Removed: In additional to a Masters of Business
−Removed: Administration, our Vice President of Information Technology holds a Certified Information Systems Security Professional certification.
+Added: In additional to a Masters of Business Administration, our Vice President of Information Technology holds a Certified Information Systems Security Professional certification.
Our Vice President of Information Technology meets with our IT Steering Committee on a routine basis.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.