4 unchanged sentences
Our enterprise risk management program considers cybersecurity risks alongside other company risks, and we consult with our cybersecurity vendor to gather information necessary to identify cybersecurity risks, evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk.
−Removed: In addition to continuous cyber monitoring,
−Removed: the IT Steering Committee participates in quarterly cyber updates with our cybersecurity vendor, which includes identification of new cyber risks and threats, reported vulnerabilities, trend analysis on attack vectors, and monitoring of risk mitigation activities.
+Added: In addition to continuous cyber monitoring, the IT Steering Committee participates in quarterly cyber updates with our cybersecurity vendor, which includes identification of new cyber risks and threats, reported vulnerabilities, trend analysis on attack vectors, and monitoring of risk mitigation activities.
The Audit Committee has ultimate oversight of cybersecurity risks and our cybersecurity risk management program.
1 unchanged sentence
These briefings include assessments of cyber risks, the threat landscape, updates on any incidents, and reports on our investments in cybersecurity risk mitigation and governance.
−Removed: Management utilizes the National Institute of Standards and Technology (NIST) Cybersecurity Framework as a guideline to manage our cybersecurity risks and inform the Audit Committee on the overall progress of our information security program.
+Added: Management utilizes the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) as a guideline to manage our cybersecurity risks and inform the Audit Committee on the overall progress of our information security program.
+Added: To ensure continued alignment and independent verification of our NIST CSF implementation, we engage a qualified third-party cybersecurity firm to conduct periodic assessments of our program, covering all five core functions of the NIST CSF.
+Added: Findings from these reviews are reported to the Audit Committee and inform our ongoing enhancements to people, process, and technology controls.
We have a formal IT Security Policy to provide appropriate governance over information security including control requirements for change management and patching, multi-factor authentication, data backup, security monitoring, mobile device management and asset management.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.