7 unchanged sentences
The Program is governed by the Technology, Information Security, and Privacy Risk Management Committee and overseen by our Board of Directors (“Board”) and its Audit, Risk and Compliance Committee (“ARC Committee”).
−Removed: The three lines of defense model is designed to provide a structure for risk accountability in the first line of defense (“FLOD”), effective challenge by the second line of defense (“SLOD”), and independent risk assurance by the third line of defense (“TLOD”).
−Removed: Our Office of the Chief Information Security Officer serves as FLOD and provides operational and technical controls and capabilities to protect against cybersecurity risks.
+Added: The three lines of defense model is designed to provide a structure for risk management in the first line of defense (“FLOD”), monitoring and guidance by the second line of defense (“SLOD”), and independent audit by the third line of defense (“TLOD”).
+Added: Our Office of the Chief Information Security Officer oversees the Company's information, cyber, and technology security.
+Added: The Enterprise Risk Management Organization provides second line monitoring and guidance.
The Technology and Information Security team serves as SLOD and provides independent oversight of our technology and cybersecurity risk mitigation practices and capabilities.
−Removed: As TLOD, Internal Audit independently assesses the effectiveness of our first and second line of defense organizations in managing cybersecurity risk and independently reports the results of audits to our ARC Committee to assist it in its oversight duties.
+Added: As TLOD, Internal Audit independently assesses the effectiveness of our cybersecurity risk management and independently reports the results of audits to our ARC Committee to assist it in its oversight duties.
Our Information Security Program includes:
16 unchanged sentences
The ARC Committee receives periodic reports from the Chief Information Security Officer (“CISO”) on our cybersecurity risks.
−Removed: Our CISO has numerous years of experience at PayPal and other organizations building security products, managing security infrastructure, providing a variety of security services, and overseeing incident response and management, escalation of security events, vulnerability scanning, and security defect management.
Management also updates the ARC Committee, as necessary, regarding cybersecurity incidents.
+Added: Our CISO is responsible for implementing the information security strategy, security engineering, enabling business partners, and securing customer data, digital assets, and payments.
+Added: His organization also monitors cyber regulation requirements and reviews impacts of new products and initiatives.
+Added: Our CISO has over two decades of experience as a cybersecurity professional, including as a CISO at PayPal and four other organizations including leading global financial services institutions and large scale U.S.
+Added: government agencies (including within the Department of Defense).
+Added: He has an extensive record of success shepherding digital transformation aligned with business goals, launching cybersecurity frameworks, building security engineering teams, ensuring protection of assets, data, privacy, and company reputation.
The ARC Committee reports to the Board regarding its activities, including those related to cybersecurity risk oversight.
The Board also receives briefings at least annually from management on our Information Security Program.
−Removed: Board members receive presentations on cybersecurity topics from our CISO and external experts from time to time as part of our continuing education to Board on topics relevant to their service as a member of our Board.
+Added: Board members receive presentations on cybersecurity topics from our CISO and external experts from time to time as part of our continuing education to the Board on topics relevant to their service as a member of our Board.
Our cybersecurity teams, overseen by our CISO, are responsible for assessing and managing our risks from cybersecurity threats, including defining security policy and board reporting of security risk.
4 unchanged sentences
The CDC team oversees, identifies, and addresses security threats aimed at safeguarding PayPal employees, consumers, and merchants.
−Removed: Our CISO organization is responsible for independently identifying, measuring, monitoring, controlling and reporting aggregate risks and for setting policies for the management and oversight of risk.
−Removed: The organization monitors cyber regulation requirements, reviews impacts of new products and initiatives, conduct reviews of cyber assessments and testing activities and provides effective challenge to the FLOD risk management activities.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.