2 unchanged sentences
Description of Cybersecurity Risk Management and Strategy
−Removed: To assess, identify and manage material cybersecurity risks, we have endeavored to implement policies, standards and technical controls with the aim of protecting our information and operations systems (collectively, “IT systems”).
+Added: To assess, identify and manage material cybersecurity risks, we have endeavored to implement policies, standards and technical controls with the aim of protecting our information technology (“IT”) and operational technology (“OT”) systems (collectively, our “IT systems”).
These standards are guided, in part, by the relevant National Institute of Standards and Technology and American Petroleum Institute frameworks.
14 unchanged sentences
Despite the implementation of our cybersecurity programs, our security measures cannot guarantee that a significant cyberattack will not occur.
−Removed: A successful attack on our IT systems or those of our vendors could have significant consequences to the business.
+Added: A successful attack on our IT systems or those of our vendors could have significant consequences to our business.
While we devote resources to our security measures to protect our systems and information, these measures cannot provide absolute security.
3 unchanged sentences
Our cybersecurity program is led by our Vice President of Information Services, North America , who reports directly to our CFO and oversees the dedicated team responsible for executing our cybersecurity strategy, including the primary assessment and management of cybersecurity risks.
−Removed: Our cybersecurity leadership team also includes our Director, Technology Risk and Cybersecurity, our Senior Director, Strategic Planning, our Senior Director, North American Solution Delivery and our Senior Director, Enterprise Technology.
−Removed: The Board receives quarterly updates on material security incidents (if applicable), detection, monitoring, security culture scores, and other key initiatives and notable events from our cybersecurity leadership team.
+Added: Our cybersecurity leadership team also includes our Senior Director, Enterprise Technology, our Director, Cybersecurity and Technology Risk, and other senior leaders from our Information Services team.
+Added: The Board receives quarterly updates on material security incidents (if applicable), detection, monitoring, and other key initiatives and notable events from our Vice President of Information Services – North America.
To facilitate effective management, our cybersecurity leadership team holds regular discussions with our dedicated cybersecurity team on cybersecurity risks, threat intelligence, incident trends, security audits, and the effectiveness of our training and testing.
1 unchanged sentence
Our cybersecurity leadership team also receives comprehensive reports on security incidents, threat intelligence, and vulnerability assessments from our cybersecurity team.
−Removed: Our cybersecurity leadership team is made up of highly experienced professionals with an extensive background in information security, risk management, and incident response.
−Removed: This background includes more than 50 years of collective experience in infrastructure, cybersecurity and telecommunications.
+Added: Our cybersecurity leadership team is made up of highly experienced professionals with extensive backgrounds in information security, risk management, and incident response, including our Vice President of Information Services – North America, our Senior Director, Enterprise Technology and our Director, Cybersecurity and Technology Risk.
+Added: Our Vice President of Information Services – North America has been with Plains for over 15 years and has over 25 years’ experience in technology infrastructure and security including senior management level oversight of cybersecurity for organizations in both the health care and oil and gas industries.
+Added: Our Senior Director, Enterprise Technology reports to the Vice President, Information Services – North America and has accountability for core enterprise technology platforms, including hosting, networks, data platforms, and cybersecurity programs.
+Added: This individual has over 20 years of experience in the information services industry, including experience with cyber incident detection and response.
+Added: The Director, Cybersecurity and Technology Risk has responsibility for oversight of cybersecurity strategy across IT and OT environments, implementation of programs aligned with recognized frameworks, and implementation of key security controls.
+Added: This individual has more than 20 years of experience in enterprise cybersecurity, OT security, and critical infrastructure risk management at publicly traded companies and holds multiple industry-recognized certifications in information security, audit, privacy, and enterprise IT governance.
In addition to having the requisite training, knowledge, skills and abilities required for their respective positions, the cybersecurity leadership team collectively holds various relevant U.S.
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.