Unresolved Staff Comments
−Removed: Not applicable.
Cybersecurity
Risk management and strategy
−Removed: We have in place certain infrastructure, systems, policies, and procedures that are designed to proactively and reactively address circumstances that arise when unexpected events such as a cybersecurity incident occur.
+Added: We have in place certain infrastructure, systems, policies, and procedures that are designed to proactively prevent or reduce the impact of, and reactively address circumstances that arise when, events such as a cybersecurity incident occur.
These include processes for assessing, identifying, and managing material risks from cybersecurity threats.
−Removed: Our information security management program generally follows processes outlined in frameworks such as the ISO 27001 international standard for Information Security and we evaluate and evolve our security measures as appropriate.
+Added: Our information security management programs generally follow certain processes outlined in frameworks such as the ISO 27001 international standard for information security management and we evaluate and evolve our security measures as appropriate.
We consult with external parties, such as cybersecurity firms and risk management and governance experts, on risk management and strategy.
1 unchanged sentence
We also have a vendor risk assessment process consisting of, depending on the nature and sensitivity of the supplier and data they process on our behalf, the distribution and review of supplier questionnaires designed to help us evaluate cybersecurity risks that we may encounter when working with third parties that have access to confidential and other sensitive company information.
−Removed: We take steps designed to ensure that such vendors have implemented data privacy and security controls that help mitigate the cybersecurity risks associated with these vendors, depending on the nature and sensitivity of the supplier and data they process on our behalf.
+Added: We take steps to review that such vendors have implemented data privacy and security controls that help mitigate the cybersecurity risks associated with these vendors, depending on the nature and sensitivity of the supplier and data they process on our behalf.
We routinely assess our high-risk suppliers’ conformance to industry standards (e.g., ISO 27001, ISO 28001, and C-TPAT), and we evaluate them for additional information, product, and physical security requirements.
9 unchanged sentences
Our executive-level leadership team also participates in cybersecurity incident response efforts by engaging with the incident response team and helping direct the company’s response to and assessment of certain cybersecurity incidents.
−Removed: We have designated a Chief Security Officer that reports to our Senior Vice President of Software Engineering to manage our assessment and management of material risks from cybersecurity threats .
+Added: We have designated a Chief Security Officer, reporting to our Senior Vice President of Software Engineering, to oversee the identification, assessment, and management of material cybersecurity risks .
Our Chief Security Officer’s cybersecurity expertise includes over 18 years of combined government and private sector assignments.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.