2 unchanged sentences
Cybersecurity
−Removed: We have certain processes for assessing, identifying and managing cybersecurity risks, which are built into our overall risk management program and are designed to help protect our information assets and operations from internal and external cyber threats and to protect the information of employees, customers, vendors, and other individuals, such as subjects enrolled in our clinical trials, from unauthorized access or attack, as well as secure our networks and systems.
−Removed: We have designed our processes based on, and periodically assess our processes against, the National Institute of Standards and Technology Cybersecurity Framework Special Publication 800-53, 800-61, rev 2, or the NIST Framework.
−Removed: This does not imply that we meet any particular technical standards, specifications, or requirements of the NIST Framework, only that we use these standards as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
−Removed: Our processes for assessing, identifying and managing cybersecurity risks include physical, procedural and technical safeguards, a cybersecurity incident response plan, regular tests on our systems, incident simulations and routine review of our policies and procedures to identify risks and improve our practices.
−Removed: We engage certain external parties, including computer security firms, to assist us with the identification, verification, and validation of cybersecurity risks, and to support mitigation efforts if necessary.
+Added: We have certain processes for identifying, assessing and managing cybersecurity risks, which are built into our overall risk management program and are designed to help protect our people, technology, products, information and operations from internal and external cyber threats and to protect the information of employees, customers, vendors, and other individuals, such as subjects enrolled in our clinical trials, from unauthorized access or attack, as well as secure our networks and systems.
+Added: Our cybersecurity program is built upon, and we periodically assess our processes against, the National Institute of Standards and Technology, or NIST, Cybersecurity Framework Special Publication 800-53, and our incident response capabilities align with NIST 800-61, revision 2, or collectively, the NIST Framework.
+Added: This does not imply that we meet any particular technical standards, specifications, or requirements of the NIST Framework, but rather only that we use these standards as a guide to help us mature our security posture in order to identify, assess, and manage cybersecurity risks relevant to our business.
+Added: Our processes for identifying, assessing and managing cybersecurity risks include physical, procedural and technical safeguards, a cybersecurity incident response plan, regular tests on our systems, incident simulations and routine review of our policies and procedures to identify risks and improve our practices.
+Added: We engage certain external parties, including information technology security firms, to assist us with the identification, verification, and validation of cybersecurity risks, and to support mitigation efforts if necessary.
We consider the internal risk oversight programs of third-party service providers before engaging them in order to help protect us from any related vulnerabilities.
3 unchanged sentences
Our management team is responsible for day-to-day assessment and management of cybersecurity risks.
−Removed: On our management team, our Chief Financial Officer, or CFO, leads the operational oversight of company-wide cybersecurity
−Removed: strategy, policy, standards and processes and works across relevant departments to assess and help prepare us and our employees, customers, vendors and other individuals to address cybersecurity risks.
−Removed: Our CFO has approximately 10 years of experience managing information technology teams of operating companies in the biotechnology industry.
−Removed: Our CFO leads a cross-functional Cybersecurity Committee, consisting of executive-level leaders and other management-level individuals with the requisite skills and education, that assists the CFO with carrying out these duties.
+Added: On our management team, our Chief Financial Officer and Chief Operating Officer , or CFO and COO , leads the operational oversight of company-wide cybersecurity strategy, policy, standards and processes and works across relevant departments to assess and help prepare us and our employees, customers, vendors and other individuals to address cybersecurity risks.
+Added: Our CFO and COO has more than ten years of experience managing information technology teams of operating companies in the biotechnology industry.
+Added: Our CFO and COO leads a cross-functional Cybersecurity Committee, consisting of executive-level leaders and other management-level individuals with the requisite skills and education, including our Executive Director IT and Cybersecurity, that assists the CFO and COO with carrying out these duties.
+Added: The Executive Director IT and Cybersecurity has over ten years of offensive and defensive cybersecurity experience with departments of the U.S.
+Added: government, international alliances and small to large biopharmaceutical companies.
Collectively, the members of our Cybersecurity Committee have notable experience in managing information security, possess the education and skills to fulfill these duties, and attend periodic trainings as necessary.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.