6 unchanged sentences
The cybersecurity team is organized into three departments:
−Removed: Protective Operations, Posture Management, and Governance, Risk, and Compliance.
+Added: Protective Operations, Vulnerability Management, and Governance, Risk, and Compliance.
Each of the three departments identifies, assesses, and manages material cybersecurity threats through specific approaches as further described below.
8 unchanged sentences
For more information about the cybersecurity risks we face, see the factors set forth under the caption “Risk Factors” in Part I, Item 1A of this report.
−Removed: Posture Management includes the vulnerability management, log operations, and architecture and engineering teams.
+Added: Vulnerability Management includes the vulnerability management, log operations, and architecture and engineering teams.
Our vulnerability management team conducts regular scans of our enterprise to look for potential weaknesses and configuration-related issues.
4 unchanged sentences
we also look for ways to prevent vulnerabilities through minimizing system ports, protocols, and services to only that which is necessary.
−Removed: Governance, Risk, and Compliance includes the risk management and compliance management teams.
−Removed: This team manages the security awareness program, compliance with cyber and privacy regulations, security policies, and prioritizes potential cyber risks that require ongoing monitoring or remediation.
+Added: Governance, Risk, and Compliance includes teams dedicated to risk and compliance management.
+Added: These teams manage the security awareness program, compliance with cyber and privacy regulations, security policies, and prioritizes potential cyber risks that require ongoing monitoring or remediation.
Identified risks are brought to the Cyber Risk Steering Committee for treatment.
1 unchanged sentence
The Company’s business segments and support teams also work closely with cybersecurity and enterprise risk management to monitor and manage third-party risks.
−Removed: Managing third-party risks includes maintaining a close and effective working relationship with the information technology procurement, accounting, and legal teams.
+Added: Managing third-party risks includes maintaining a close and effective working
+Added: relationship with the information technology procurement, accounting, and legal teams.
In addition to identifying risks as part of the third-party selection process, we continuously monitor our third parties using products and services that provide us insight into their attack surface, threats that can impact us through them, and real-world security posture.
2 unchanged sentences
The Company has an independent internal audit team that conducts audits based on their own methodology and assessment and we utilize external cybersecurity auditors, where applicable.
−Removed: In addition, certain lines of business utilize other third-party cybersecurity auditors for PCI DSS assessments and PCI ASV scans;
+Added: In addition, certain lines of business utilize other third-party cybersecurity auditors for Payment Card Industry Data Security Standard (PCI DSS) assessments and PCI Approved Scanning Vendor (ASV) scans;
and we are routinely audited by our customers.
1 unchanged sentence
The Board Risk and Finance Committee receives regular reports from the Chief Risk Officer and Chief Security Officer on key company risks and emerging threats.
−Removed: These reports also include cybersecurity monitoring and
−Removed: threat response metrics, industry trends and educational materials, risk mitigation strategies, regulatory requirements, corporate policies, third-party risk metrics, cybersecurity tools and resources, incident response plans, and other areas of importance.
+Added: These reports also include cybersecurity monitoring and threat response metrics, industry trends and educational materials, risk mitigation strategies, regulatory requirements, corporate policies, third-party risk metrics, cybersecurity tools and resources, incident response plans, and other areas of importance.
The Company's headquarters is located in Lincoln, Nebraska.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.