6 unchanged sentences
and includes an identification of our top risks, including cybersecurity risks;
−Removed: (2) formalized security and privacy reviews designed
−Removed: to identify risks from many new features, software, and vendors;
−Removed: (3) a vulnerability management program designed to identify hardware
−Removed: and software vulnerabilities;
−Removed: (4) an internal “red team” program, which simulates cyber threats, intended to allow us to
−Removed: fix vulnerabilities before threat actors identify them;
+Added: (2) formalized security and privacy reviews designed to
+Added: identify risks from many new features, software, and vendors;
+Added: (3) a vulnerability management program designed to identify hardware and
+Added: software vulnerabilities;
+Added: (4) an internal “red team” program, which simulates cyber threats, intended to allow us to fix vulnerabilities
+Added: before threat actors identify them;
(5) a threat intelligence program designed to model and research our adversaries;
−Removed: and (6) a privacy and security incident response program designed to investigate, respond to, and remediate known incidents.
−Removed: These processes
−Removed: vary in scope and maturity across the business and are processes we work to continually improve.
−Removed: Our risk management approach is supplemented
−Removed: by external and internal enterprise risk management audits, which are designed to test the effectiveness of our security controls.
−Removed: conduct penetration testing on a periodic basis, and have established an external bug bounty program to allow security researchers to
−Removed: help identify vulnerabilities and weaknesses in our controls and configurations in our systems.
−Removed: We also maintain a vendor risk management
−Removed: program designed to identify and mitigate potential risks associated with third-party suppliers and business partners.
−Removed: This program includes
−Removed: pre-engagement diligence, use of contractual cybersecurity and notification provisions, and ongoing monitoring of vendors, as appropriate.
+Added: and (6) a privacy
+Added: and security incident response program designed to investigate, respond to, and remediate known incidents.
+Added: These processes vary in scope
+Added: and maturity across the business and are processes we work to continually improve.
+Added: Our risk management approach is supplemented by
+Added: external and internal enterprise risk management audits, which are designed to test the effectiveness of our security controls.
+Added: penetration testing on a periodic basis, and have established an external bug bounty program to allow security researchers to help identify
+Added: vulnerabilities and weaknesses in our controls and configurations in our systems.
+Added: We also maintain a vendor risk management program designed
+Added: to identify and mitigate potential risks associated with third-party suppliers and business partners.
+Added: This program includes pre-engagement
+Added: diligence, use of contractual cybersecurity and notification provisions, and ongoing monitoring of vendors, as appropriate.
We use third-party service providers to assist
2 unchanged sentences
The material cybersecurity threats identified
−Removed: through these processes are managed by our CISO and, where appropriate, our risk and compliance committee, in consultation with management.
−Removed: Together, they identify responsive actions for inclusion in our annual strategic planning, or earlier resolution depending on the nature
+Added: through these processes are managed by our Chief Technology Officer and, where appropriate, our risk and compliance committee, in consultation
+Added: with management.
+Added: Together, they identify responsive actions for inclusion in our annual strategic planning, or earlier resolution depending
+Added: on the nature of the risk.
For a description of the risks from cybersecurity
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.