13 unchanged sentences
of an inventory of information systems (“Information Systems”) employed by the Sponsor of the Trust either directly or through
−Removed: Information Systems include electronic and physical systems used to store, process or transmit information either directly or
−Removed: through a service provider.
+Added: Information Systems include electronic and physical systems used to store, process or transmit information either directly
+Added: or through a service provider.
This includes all methods of data processing, transmission, and retention, both electronic and physical.
−Removed: Information Systems used by on behalf of the Trust must, at a minimum, adequately address security elements consistent with applicable
−Removed: state and local regulatory requirements and best practices pertaining to:
+Added: Electronic Information Systems used by on behalf of the Trust must, at a minimum, adequately address security elements consistent with
+Added: applicable state and local regulatory requirements and best practices pertaining to:
Data Storage,
5 unchanged sentences
The CISO is responsible for classifying information, identifying risks, and identifying risk mitigation strategies.
−Removed: CISO is also responsible for evaluating the adequacy of risk mitigation strategies prior to deploying any Information System.
+Added: The CISO is also responsible for evaluating the adequacy of risk mitigation strategies prior to deploying any Information System.
hosted applications (those not installed on the Sponsor’s local network and servers) are reviewed by the CISO at least annually
6 unchanged sentences
Risk Mitigation
−Removed: The CISO will identify processes or controls to
−Removed: mitigate identified risks to the security or integrity of each Information System.
+Added: The CISO will identify processes or controls
+Added: to mitigate identified risks to the security or integrity of each Information System.
The computer system security requirements set forth
13 unchanged sentences
The CISO must evaluate the risk mitigation strategies for ongoing adequacy.
−Removed: The evaluation must be documented in
−Removed: a form prescribed by the CISO.
+Added: The evaluation must be documented
+Added: in a form prescribed by the CISO.
If the CISO concludes that risk mitigation strategies are inadequate for an Information System containing
−Removed: confidential or internal information, action will be taken to either correct the inadequacy in a timely manner or discontinue use of the
−Removed: Information System.
+Added: confidential or internal information, action will be taken to either correct the inadequacy in a timely manner or discontinue use of
+Added: the Information System.
Cybersecurity Procedures
1 unchanged sentence
the cybersecurity policy applicable to the Trust, which include the following:
−Removed: The Sponsor maintains system access rights and controls for the Trust including:
−Removed: restricting Supervised Persons’ (a “Supervised Person” is each employee, officer, member, and other persons who are subject to the Sponsor’s supervision and control) network resources access to the systems which are necessary for their business functions,
+Added: The Sponsor maintains system access rights and controls for the Trust
+Added: restricting Supervised Persons’ (a “Supervised Person”
+Added: is each employee, officer, member, and other persons who are subject to the Sponsor’s supervision and control) network resources
+Added: access to the systems which are necessary for their business functions,
use of passwords,
1 unchanged sentence
secure remote access protocols;
−Removed: The Sponsor maintains its systems carrying Trust data with appropriate updates and virus protections;
−Removed: The Sponsor promptly eliminates access to all networks, devices, and resources as part of its HR procedures in the event a Supervised Person resigns or is terminated.
−Removed: Such Supervised Person is required to immediately return all Sponsor-related equipment and information to the CISO;
−Removed: The Sponsor has adopted procedures governing the use of mobile devices for the business purposes affecting the Trust;
−Removed: The Sponsor prohibits Supervised Persons from installing software on company owned equipment without first obtaining approval from the CISO or other designated person(s);
−Removed: The CISO or other designated person(s) conducts periodic monitoring of the networks affecting the Trust to detect potential cybersecurity events;
−Removed: The CISO or other designated person(s) conducts periodic monitoring of the networks affecting the Trust to detect unauthorized data transfers;
−Removed: Security procedures to protect information that is electronically stored or transmitted include authentication protocols;
+Added: The Sponsor maintains its systems carrying Trust data with appropriate
+Added: updates and virus protections;
+Added: The Sponsor promptly eliminates access to all networks, devices, and
+Added: resources as part of its HR procedures in the event a Supervised Person resigns or is terminated.
+Added: Such Supervised Person is required
+Added: to immediately return all Sponsor-related equipment and information to the CISO;
+Added: The Sponsor has adopted procedures governing the use of mobile devices
+Added: for the business purposes affecting the Trust;
+Added: The Sponsor prohibits Supervised Persons from installing software on
+Added: company owned equipment without first obtaining approval from the CISO or other designated person(s);
+Added: The CISO or other designated person(s) conducts periodic monitoring
+Added: of the networks affecting the Trust to detect potential cybersecurity events;
+Added: The CISO or other designated person(s) conducts periodic monitoring
+Added: of the networks affecting the Trust to detect unauthorized data transfers;
+Added: Security procedures to protect information that is electronically stored
+Added: or transmitted include authentication protocols;
secure access control measures, and encryption of all transmitted files;
−Removed: All suspicious activity involving the Information Systems affecting the Trust recognized or uncovered by personnel should be promptly reported to his or her supervisor and/or the CISO;
+Added: All suspicious activity involving the Information Systems affecting
+Added: the Trust recognized or uncovered by personnel should be promptly reported to his or her supervisor and/or the CISO;
● A Supervised Person must immediately notify his or her supervisor and/or the CISO to report a lost or stolen laptop, mobile device, and/or flash drive.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.