6 unchanged sentences
Our cybersecurity governance and strategy program to prevent, detect, manage, mitigate, and remediate cyber threats is comprised of:
−Removed: • Controls based upon the NIST Cybersecurity Framework for enterprise governance, critical asset management, internal and third-party risk management, segregated access control management, data security and protection,
−Removed: anomaly logging and general security monitoring, incident response, security training and awareness, and disaster recovery testing.
+Added: • Controls based upon the NIST Cybersecurity Framework for enterprise governance, critical asset management, internal and third-party risk management , segregated access control management, data security and protection, anomaly logging and general security monitoring, incident response, security training and awareness, and disaster recovery testing.
• Security Policies and Procedures for cybersecurity, incident response, acceptable use, change control, disaster recovery, backup and recovery, business continuity, business operations recovery, third-party vendor security assessments , vulnerability and patch management, data privacy, and various regulatory compliance areas.
1 unchanged sentence
This risk management framework incorporates corporate and business segment SCADA (Supervisory Control and Data Acquisition) system risks for an integrated enterprise approach.
−Removed: • Various Cybersecurity Systems and Protocols for aggregated monitoring, detection and response, network protection and segmentation, layered security methods, vulnerability and patch management, backup and recovery, and asset management.
+Added: • Various Cybersecurity Systems and Protocols for aggregated monitoring and behavior analytics, detection and response, network protection and segmentation, layered security methods for defense-in-depth, vulnerability and patch management, backup and recovery, and asset management.
• Employee Education for continual security awareness and threat diligence.
19 unchanged sentences
Our CIO has a Bachelor of Science in Management Information Systems and holds the Certified Information Systems Audit security certification as well.
−Removed: Our security members are comprised of various industry technology skilled resources in cybersecurity, business continuity and system recovery, event management, system administration, network engineering, and regulatory compliance with a collective 100 plus years of experience.
+Added: Our security members are comprised of various industry technology skilled resources in cybersecurity, business continuity and
+Added: system recovery, event management, system administration, network engineering, and regulatory compliance with a collective 100 plus years of experience.
Security operations partners are also leveraged for 24x7x365 managed detection and response support plus provide expert cybersecurity resources as an extension of our team.
3 unchanged sentences
• An annual presentation overview of our cyber controls and related systems for a comprehensive understanding of our cybersecurity protection and resilience;
−Removed: • Quarterly cybersecurity training on topics such as ransomware, phishing, impersonation, social engineering, third-party security risks, and business email compromise to reinforce general security knowledge;
+Added: • Quarterly cybersecurity training on topics such as ransomware, phishing, impersonation, social engineering, third-party security risks , business email compromise, and artificial intelligence to reinforce general security knowledge;
• Monthly cybersecurity newsletter distribution for current threat tactics and general security awareness.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.