20 unchanged sentences
As part of our risk assessment process, we incorporate results from procedures performed by third-party consultants.
−Removed: We utilize third-party consultants to complete risk quantification analysis and perform penetration and vulnerability testing and monitoring, as well as overall cybersecurity control testing.
+Added: We utilize third-party consultants to perform penetration and vulnerability testing and monitoring, as well as overall cybersecurity control testing.
Potential risks associated with the use of third-party service providers are monitored and managed through an established service provider management policy.
1 unchanged sentence
In managing cybersecurity risk, we employ a defense-in-depth strategy and regularly monitor our cyber environment for potential new threats.
−Removed: Our strategy includes employee training and awareness on cybersecurity risks and related best practices, required password complexity, the use of multi-factor authentication, information security protocols, anti-virus and anti-ransomware software, a patch management program, the execution of tabletop exercises on a periodic basis, established policies and protocols for cyber incident response planning and reporting, and ongoing internal cybersecurity testing.
+Added: Our strategy includes employee training and awareness on cybersecurity risks and related best practices, required
+Added: password complexity, the use of multi-factor authentication, information security protocols, anti-virus and anti-ransomware software, a patch management program, the execution of tabletop exercises on a periodic basis, established policies and protocols for cyber incident response planning and reporting, and ongoing internal cybersecurity testing.
At the management level, our cyber program is managed by our ICSP group.
1 unchanged sentence
The ICSP group is in charge of developing, maintaining and measuring compliance with the information and cybersecurity governance program, as well as monitoring cyber incidents and implementing mitigation measures as part of an evolving, dynamic external environment.
−Removed: Our approach to cybersecurity incident reporting and response planning is governed by our incident response plans established for
−Removed: T able of Contents
−Removed: each of our business units.
+Added: Our approach to cybersecurity incident reporting and response planning is governed by our incident response plans established for each of our business units.
The plans outline the processes related to detecting, assessing, investigating, mitigating and remediating cyber incidents, as well the communication and reporting plan and the required personnel to be included in the process and communications.
1 unchanged sentence
Our business risk management group works closely with our ICSP group to regularly assess and identify possible material risks from cybersecurity threats, including but not limited to, financial, operations, reputational and regulatory impact to the Company, as well as impacts on our employees and customers.
−Removed: Their risk assessment results are reported to the Executive Risk Committee on a quarterly basis.
+Added: Their risk assessment results are reported to our Executive Risk Committee on a quarterly basis.
The Executive Risk Committee, which is comprised of our executive officers, meets quarterly to identify and assess short-, medium- and long-term risks, and to ensure adequate mitigation strategies are implemented.
During these meetings, the Executive Risk Committee reviews significant and emerging risks, including cybersecurity risks, and assesses the Company’s plans to mitigate or otherwise manage and monitor those risks.
−Removed: Our Board of Directors provides oversight of our cybersecurity program through quarterly and annual risk review and cybersecurity reporting.
+Added: Our Board of Directors provides oversight of our cybersecurity program through quarterly and annual risk reviews and cybersecurity reporting.
On a quarterly basis, cybersecurity risk and mitigation strategies are reviewed as part of our business risk management group's reporting to the Board of Directors, which includes the reporting of significant business risks, including cybersecurity mitigation strategies employed to manage these risks and a review of any emerging risks.
−Removed: Annually, our Vice President of IT provides an overview of our cybersecurity program to the Board of Directors, including a review of key strategies, emerging risks and a summary of key performance indicators.
+Added: At least annually, our Vice President of IT provides an overview of our cybersecurity program to the Board of Directors , including a review of key strategies, emerging risks and a summary of key performance indicators.
In addition, annually the Board of Directors reviews the results of our penetration and vulnerability testing.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.