7 unchanged sentences
The IT manager provides an IT status report to the Risk Management committee on a quarterly basis.
+Added: Our IT department performs annual risk assessments to evaluate the effectiveness of the controls to support the requirements under Gramm-Leach Bliley Act ("GLBA"), and Federal Institutions Examination Council ("FFIEC") Guidance on Securing Customer Information.
+Added: The focus areas include:
+Added: • technology systems used for information that is collected, processed, and stored;
+Added: • assessing internal and external cybersecurity threats and vulnerabilities;
+Added: • performing regular penetration and controls testing;
+Added: • evaluation and assessment of impact should the information or systems become compromised;
+Added: • evaluation for the effectiveness of the governance structure for Information security risk management.
+Added: Internal and external Penetration Testing is performed annually.
+Added: Tests are conducted or reviewed by independent third parties or qualified Associates independent of those that develop or maintain the security program.
+Added: Testing is performed annually by third party auditors contracted through the company's IT department.
+Added: Management reviews test results promptly and ensures that appropriate steps are taken to address adverse test results.
+Added: Remediation efforts are organized and made available to the Committee as well as for review by third party auditors and examiners.
The Company has adopted an Incident Response Plan (the “Plan”) to monitor, detect, mitigate and remediate cybersecurity incidents.
The Plan requires all employees to have a working knowledge of the Company’s Information Security Program and Incident Response Policies.
−Removed: Pursuant to the Plan, the Information Technology Administrator and Senior\Compliance Management identify information owners for sensitive customer information and create an incident
−Removed: response team.
+Added: Pursuant to the Plan, the Information Technology Administrator and Senior\Compliance Management identify information owners for sensitive customer information and create an incident response team.
Each Department Manager, upon notification of a potential unauthorized access, manipulation of data or theft of any item identified under GLBA Inventory and Asset Classification, is responsible for further assessing the situation in order to document the suspected or actual breech, and forward the appropriate documentation to the Information Technology Administrator.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.