5 unchanged sentences
Management’s Role in Managing Risk
−Removed: At the management level, primary responsibility for assessing and managing material risks from cybersecurity threats rests with our Vice President, Corporate Information Security, Risk & Compliance ("VP, CIS").
−Removed: Our VP, CIS has over two decades of experience in information technology and cybersecurity.
−Removed: The VP, CIS reports to our Chief Information Officer (“CIO”) who has significant experience leading technology teams at large public companies and our CIO reports to our Chief Technology Officer.
−Removed: Our approach to managing cybersecurity risk is informed by the industry-standard National Institute for Standards and Technology Cybersecurity Framework.
−Removed: The VP, CIS has primary responsibility for implementing and overseeing our enterprise-wide cybersecurity strategy, policy, architecture and processes.
+Added: At the management level, primary responsibility for assessing and managing material risks from cybersecurity threats rests with our Vice President, Foundational Technology & Services ("VP, FTS") who has over two decades of experience in data and information technology.
+Added: The work within this organization is managed by two senior leaders, who each have over two decades of experience in information technology and cybersecurity.
+Added: The VP, FTS reports to our Chief Technology Officer, who has significant experience leading technology teams at large public companies.
+Added: Our approach to managing cybersecurity risk is informed by the industry-standard National Institute of Standards and Technology Cybersecurity Framework.
+Added: The VP, FTS has primary responsibility for implementing and overseeing our enterprise-wide cybersecurity strategy, policy, architecture and processes.
We use various tools and methodologies to identify and manage cybersecurity risk, including risk assessments and a vulnerability management program that includes periodic penetration testing.
15 unchanged sentences
Risks from Cybersecurity Threats
−Removed: Even though, to date, cybersecurity risks have not materially affected our business or our results of operations, we face numerous and evolving cybersecurity threats.
−Removed: There can be no assurance that we, or the third parties with which we interact, will not face a cybersecurity incident in the future that will materially affect us.
−Removed: For more information about the cybersecurity risks we face, see the risk factor entitled “We rely significantly on information technology to operate our business, including our supply chain and retail operations, and any failure, inadequacy or interruption of that technology could harm our ability to effectively operate our business” in Item 1A.
+Added: Even though, to date, cybersecurity risks have not materially affected our business or our results of operations, we have experienced cybersecurity incidents in the past and continue to face numerous and evolving cybersecurity threats.
+Added: There can be no assurance that we, or the third parties with which we interact, will not experience a cybersecurity incident in the future that will materially affect us.
+Added: For additional information about the cybersecurity risks we face, see the risk factor entitled “We rely significantly on information technology to operate our business, including our supply chain and retail operations, and any failure, inadequacy or interruption of that technology could harm our ability to effectively operate our business” in Item 1A.
Risk Factors.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.