6 unchanged sentences
Our cybersecurity governance and strategy program to prevent, detect, manage, mitigate, and remediate cyber threats is comprised of:
−Removed: • Controls based upon the NIST Cybersecurity Framework for enterprise governance, critical asset management, internal and third-party risk management , segregated access control management, data security and protection, anomaly logging and general security monitoring, incident response, security training and awareness, and disaster recovery testing.
−Removed: • Security Policies and Procedures for cybersecurity, incident response, acceptable use, change control, disaster recovery, backup and recovery, business continuity, business operations recovery, third-party vendor security assessments , vulnerability and patch management, data privacy, and various regulatory compliance areas.
−Removed: • Enterprise Risk Management to identify, assess and mitigate internal and third-party risks in a continuous life cycle program which is also based on the NIST Cybersecurity Framework.
+Added: • Controls based upon the NIST Cybersecurity and Artificial Intelligence Frameworks for enterprise governance, critical asset management, internal and third-party risk management , segregated access control management, data
+Added: security and protection, anomaly logging and general security monitoring, incident response, security training and awareness, and disaster recovery testing.
+Added: • Security Policies and Procedures for cybersecurity, incident response, acceptable use, change control, artificial intelligence, disaster recovery, backup and recovery, business continuity, business operations recovery, third-party vendor security assessments , vulnerability and patch management, data privacy, and various regulatory compliance areas.
+Added: • Enterprise Risk Management to identify, assess and mitigate internal and third-party risks in a continuous life cycle program which is also based on the NIST Cybersecurity and Artificial Intelligence Frameworks.
This risk management framework incorporates corporate and business segment SCADA (Supervisory Control and Data Acquisition) system risks for an integrated enterprise approach.
9 unchanged sentences
Monthly, the Compliance and Security Steering Committee meets to review risk register, current threat assessments and related mitigation efforts for risk management tracking.
−Removed: Additionally, on a quarterly basis, our Chief Information Officer (“CIO”) presents the risk score and mitigation updates to the board of directors of our GP for risk oversight.
+Added: Additionally, on a quarterly basis, our Chief Information Officer (“CIO”) presents Cybersecurity metrics, goals and projects including security remediation (when applicable) to the board of directors of our GP risk oversight.
Event management of a cyber incident follows our Cybersecurity Policy Incident Response Procedure (“Incident Response Policy”) which is based upon the NIST framework.
9 unchanged sentences
Our CIO has a Bachelor of Science in Management Information Systems and holds the Certified Information Systems Audit security certification as well.
−Removed: Our security members are comprised of various industry technology skilled resources in cybersecurity, business continuity and
−Removed: system recovery, event management, system administration, network engineering, and regulatory compliance with a collective 100 plus years of experience.
+Added: Our security members are comprised of various industry technology skilled resources in cybersecurity, business continuity and system recovery, event management, system administration, network engineering, and regulatory compliance with a collective
+Added: 100 plus years of experience.
Security operations partners are also leveraged for 24x7x365 managed detection and response support plus provide expert cybersecurity resources as an extension of our team.
5 unchanged sentences
• Monthly cybersecurity newsletter distribution for current threat tactics and general security awareness.
−Removed: Additionally, the CIO presents a quarterly cyber update to the board of directors of our GP for an overview of cyber program key metrics and trends, cyber event executive summaries (based upon occurrence), fiscal year security goals and tracking progression, risk register scoring, and status updates on cyber related projects.
+Added: Additionally, the CIO presents a quarterly cyber update to the board of directors of our GP for an overview of cyber program key metrics and trends, cyber event executive summaries (based upon occurrence), fiscal year security goals and tracking progression, and status updates on cyber related projects and associated risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.