Unresolved Staff Comments
−Removed: As of the date of this report, we do not have any open comments from the SEC related to our financial statements or periodic filings.
+Added: As of the date of this report, we do not have any unresolved comments from the SEC related to periodic or current reports under the Exchange Act.
Cybersecurity
15 unchanged sentences
We also engage third-party resources to assist in our cybersecurity program, including annual ISO 27001 assessments of our cybersecurity program, validation of our SOC2 controls' operational effectiveness for certain products, and retaining leading cybersecurity experts as needed in response to cybersecurity incidents and for other consultative needs (e.g., due diligence of potential acquisitions).
−Removed: Our multi-level cybersecurity governance and risk management structure begins with our management-level Enterprise Risk Management ("ERM") Committee, which consists of cross-functional management representatives throughout Progress.
−Removed: The ERM Committee receives detailed cybersecurity information from key security personnel, led by our Chief Information Security Officer ("CISO") , and reports to Progress’ Chief Executive Officer, Chief Financial Officer, Chief Information Officer, Chief Legal Officer, and other members of CEO Staff at least quarterly.
+Added: Our multi-level cybersecurity governance and risk management structure begins with our management-level Enterprise Risk Management ("ERM") Committee, which consists of cross-functional management representatives from throughout Progress.
+Added: The ERM Committee receives detailed cybersecurity information from key security personnel, led by our Chief Information Security Officer ("CISO") , and reports to Progress' Chief Executive Officer, Chief Financial Officer, Chief Information Officer, Chief Legal Officer, and other members of our executive team at least quarterly.
Our CISO has significant information technology experience, having served in various roles in information technology and information security for more than 20 years, including serving in various cybersecurity leadership roles within public and private companies.
−Removed: He holds an undergraduate degree in management and obtained CISO Executive Education Certification from Carnegie Mellon University.
+Added: He holds an undergraduate degree in management and obtained a CISO Executive Education Certification from Carnegie Mellon University.
Cybersecurity leaders reporting to our CISO also have significant relevant experience and industry recognized certifications.
−Removed: Our CISO has routinely reported to the Audit Committee of our Board of Directors at the Audit Committee’s regular quarterly meetings, or more frequently as needed.
+Added: Our CISO routinely reports to the Audit Committee of our Board of Directors at the Audit Committee's regular quarterly meetings, or more frequently as needed.
The Audit Committee's duties include, among other things, oversight of risks related to cybersecurity, as well as our broader ERM program.
6 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.