1 unchanged sentence
CYBERSECURITY
−Removed: As a global aerospace and defense company serving commercial and government customers in the aerospace industry and domestic and international military and government customers as a defense contractor, we are the target of advanced and
−Removed: persistent cyber-attacks from a variety of threat actors.
−Removed: Our products and services are highly sophisticated and specialized, involve complex advanced technologies including information technology systems, and process, store, or transmit highly sensitive unclassified and classified information.
+Added: As a global aerospace and defense company serving commercial and government customers in the aerospace industry and domestic and international military and government customers as a defense contractor, we are the target of advanced and persistent cyber-attacks from a variety of sources.
+Added: Our products and services are highly sophisticated and specialized, involve complex advanced technologies including information technology (IT) systems, and process, store, or transmit highly sensitive unclassified and classified information.
Moreover, our products and services are often integrated with third-party products and services.
−Removed: Cybersecurity threats include attacks on, or other attempts to infiltrate, our information technology (IT) infrastructure and the IT infrastructure of our customers, suppliers, subcontractors and other third parties, attempting to gain unauthorized access to our confidential or other proprietary information, classified information, or information relating to our employees, customers, and other third parties, or to disrupt our systems or the systems of our customers, suppliers, subcontractors, and other third parties.
−Removed: Cybersecurity threats also include attempts to infiltrate our products or services, including attacks targeting the security, confidentiality, integrity and/or availability of the hardware, software and information installed, stored or transmitted in our products, including after the purchase of those products and when they are incorporated into third-party products, facilities, or infrastructure.
+Added: Cybersecurity threats include attacks on, or other attempts to infiltrate, our IT infrastructure and the IT infrastructure of our customers, suppliers, subcontractors, and other third parties, attempting to gain unauthorized access to our confidential or other proprietary information, classified information, or information relating to our employees, customers, and other third parties, or to disrupt our systems or the systems of our customers, suppliers, subcontractors, and other third parties.
+Added: Cybersecurity threats also include attempts to infiltrate our products or services, such as attacks targeting the security, confidentiality, integrity or availability of the hardware, software and information installed, stored, or transmitted in our products, which may occur after the purchase of those products or when they are incorporated into third-party products, facilities, or infrastructure.
Our Cybersecurity Program
3 unchanged sentences
Enterprise Cybersecurity.
−Removed: Our enterprise cybersecurity program aligns with the National Institute of Standards and Technology (NIST) standards, among others.
−Removed: The program includes processes and controls for the deployment of new IT systems by the Company and controls over new and existing system operation.
+Added: Our enterprise cybersecurity program aligns with the National Institute of Standards and Technology (NIST) standards.
+Added: Our program includes processes and controls for the deployment of new IT systems by the Company and controls over new and existing system operation.
We monitor and conduct regular testing of these controls and systems, including vulnerability management through active discovery and testing to regularly assess patching and configuration status.
−Removed: In addition, we require our employees and contract workers to complete annual cybersecurity training, and we regularly conduct simulated phishing and cyber-related communications.
+Added: In addition, we require our employees and contract workers to complete annual cybersecurity training, and we regularly conduct simulated phishing and cyber-related communications to educate individuals on the latest threats.
Product and Services Cybersecurity.
−Removed: Our product development processes apply development, security and operations principles aligned with applicable government and commercial standards including DO-326 and NIST standards and guideline publications, and include vulnerability scanning and static and dynamic composition analysis.
+Added: Our product development processes apply development, security, and operations principles aligned with applicable government and commercial standards, and include vulnerability scanning and static and dynamic composition analysis.
We regularly assess our product development processes, product cyber maturity, and the teams providing our secure services in relation to cybersecurity.
In addition, we strive to meet all security requirements mandated by government and commercial customers and adhere to regulatory guidance and standards for system security engineering.
−Removed: Many of our products also undergo industry audits and regulatory compliance certifications, and our products delivered to the Department of Defense (DoD) must comply with DoD risk management requirements where required.
−Removed: Cybersecurity for U.S.
−Removed: Government Authorized Systems.
−Removed: With respect to products and services provided to, and information technology systems used in connection with programs for, the U.S.
−Removed: government, our cybersecurity program aligns with the NIST standard and meets the requirements of 32 CFR Part 117 and other applicable U.S.
+Added: Many of our products also undergo industry audits and regulatory compliance certifications, and our products delivered to the Department of Defense (DoD) must comply with DoD risk management requirements.
+Added: Cybersecurity for Systems used in Support of U.S.
+Added: Government Customers.
+Added: With respect to products and services provided to, and IT systems used in connection with programs for, the U.S.
+Added: government, our cybersecurity program aligns with the NIST standards and meets the requirements of 32 CFR Part 117 and other applicable U.S.
government guidance.
−Removed: The program includes authorization and assessment of new and existing IT systems by our customer.
+Added: The program includes authorization and assessment of new and existing IT systems by our customers and third parties.
We monitor use on these systems, including vulnerability management through patching and configuration.
1 unchanged sentence
Incident Response.
−Removed: Our cybersecurity program includes monitoring for potential security threats that may lead to vulnerabilities.
+Added: Our cybersecurity program includes monitoring for potential security threats that may lead to exploitation of vulnerabilities.
We evaluate and assign severity levels to incidents, escalate and engage incident response teams based on severity, and manage and mitigate the related risks.
−Removed: Incidents are reported internally to members of senior management and/or the Board of Directors as appropriate based on severity and incident type and are also analyzed for external reporting requirements.
−Removed: Our incident response process is also designed to coordinate functions to enable continuity of essential business operation in the event of a cyber crisis.
+Added: Incidents are reported internally to members of senior management and the Board of Directors as appropriate based on severity and incident type and are also analyzed for external reporting requirements.
+Added: Our incident management process is designed to coordinate functions to enable continuity of essential business operation in the event of a cyber crisis.
Third-Party Service Providers.
1 unchanged sentence
Management of Third-Party Risks.
−Removed: Our suppliers, subcontractors and third-party service providers are subject to cybersecurity obligations and controls.
−Removed: Prior to engagement, we assess the cybersecurity posture of third-party service providers who store, process, or transmit our information as a service, or connect to our networks.
−Removed: We also require our suppliers, subcontractors and third-party service providers to agree to cybersecurity-related contractual terms and conditions of purchase.
−Removed: Many of these third parties are also subject to regulatory requirements in mandatory government procurement clauses, including those contained in the U.S.
−Removed: Federal Acquisition Regulation and U.S.
−Removed: Defense Federal Acquisition Regulation Supplement, which obligate adherence to a generally accepted cybersecurity framework, such as NIST, and occasional
−Removed: assessment of their implementation of cybersecurity controls as a condition of contract award or during contract performance.
+Added: Our suppliers, subcontractors, and other third-party service providers are subject to cybersecurity obligations and controls.
+Added: We assess and periodically reassess the cybersecurity posture of third-party service providers who store, process, or transmit our information as a service, or connect to our networks.
+Added: We also require our suppliers, subcontractors, and other third-party service providers to agree to cybersecurity-related contractual terms and conditions of purchase.
+Added: Many of these third parties are also subject to regulatory requirements in mandatory government procurement clauses, including those contained in the Federal Acquisition Regulation (FAR) and the Defense Federal Acquisition Regulation Supplement (DFARS).
+Added: Among other things, mandatory government procurement clauses obligate adherence to a generally accepted cybersecurity framework, such as NIST, and occasional assessment of the implementation of cybersecurity controls as a condition of contract award or during contract performance.
Finally, we require these third parties to notify us of cybersecurity incidents that impact us.
2 unchanged sentences
Our cybersecurity program is regularly assessed through management self-evaluation and ongoing monitoring procedures to evaluate our program effectiveness, including assessments associated with internal controls over financial reporting as well as vulnerability management through active discovery and testing to validate patching and configuration.
−Removed: Additionally, our Internal Audit function regularly assesses our program effectiveness through audits of our entities, systems and processes to help maintain compliance with policies.
+Added: Additionally, our Internal Audit function regularly assesses our program effectiveness through audits of our systems and processes to help maintain compliance with policies.
As cybersecurity threats are continuously evolving, we also periodically engage with third parties to perform maturity assessments of our program to identify potential risk areas and improvement opportunities.
−Removed: This includes assessment of our overall program, policies and processes, compliance with regulatory requirements and an overall assessment of key vulnerabilities.
+Added: This includes assessment of our overall program, policies and processes, compliance with regulatory requirements, and assessment of key vulnerabilities.
We use these assessments to supplement our own evaluation of the overall health of our program and target improvement areas.
−Removed: Several external organizations also evaluate our enterprise cybersecurity program, including the U.S.
−Removed: Defense Contract Management Agency (DCMA) and Cybersecurity Maturity Model Certificate (CMMC) Third Party Assessment Organization.
+Added: Several external organizations also evaluate our enterprise cybersecurity program, including the Defense Contract Management Agency (DCMA) and Cybersecurity Maturity Model Certification Third-Party Assessment Organization.
Moreover, some of our products are audited or reviewed for regulatory compliance certification pursuant to the relevant DoD risk management framework.
2 unchanged sentences
Our Board of Directors has primary oversight responsibility for enterprise cybersecurity risks.
−Removed: The Special Activities Committee supports the Board in oversight of classified business cybersecurity, including with respect to company internal information and operational technology systems.
+Added: The Special Activities Committee of the Board supports the Board in oversight of classified business cybersecurity, including with respect to Company internal information and operational technology systems.
The Audit Committee also considers enterprise cybersecurity risks in connection with its financial and compliance risk oversight role.
Our global chief information security officer (CISO) , under the direction of our chief digital officer, leads our enterprise cybersecurity program and is responsible for assessing and managing enterprise cybersecurity risks.
−Removed: Our CISO regularly updates the Board of Directors on cybersecurity risks as they relate to our information and operational technology systems and our suppliers and partners, in addition to updates on enterprise cybersecurity incidents and key Company defenses and mitigation strategies.
−Removed: Our CISO is an experienced cybersecurity senior executive with more than 25 years’ experience building and leading cybersecurity, risk management, and information technology teams.
+Added: Our CISO regularly updates the Board of Directors on cybersecurity risks as they relate to our information and operational technology systems, our suppliers, and other third-party service providers, in addition to updates on enterprise cybersecurity incidents and key Company defenses and mitigation strategies.
+Added: Our CISO is an experienced cybersecurity senior executive with more than 25 years’ experience building and leading cybersecurity, risk management, and IT teams.
In performing his role, he regularly reviews enterprise cybersecurity risks, controls, program policy, and processes, including training, oversees policy and program development, implementation and updates, and informs senior leadership on cybersecurity-related issues and activities affecting the organization.
2 unchanged sentences
The Special Activities Committee of our Board of Directors has primary oversight responsibility for cybersecurity risks related to our products and services.
−Removed: The full Board of Directors also receives periodic briefings from management on the Company’s product cybersecurity risks and programs.
+Added: The full Board of Directors also receives periodic briefings from management regarding the Company’s products and services cybersecurity risks.
The Audit Committee also considers product and services cybersecurity risks in connection with its financial and compliance risk oversight role.
5 unchanged sentences
Enterprise Risk Management
−Removed: Our cybersecurity risk processes are a key element of our Enterprise Risk Management (ERM) process, which is designed to identify and evaluate the full range of significant risks to RTX Corporation (RTX).
+Added: Our cybersecurity risk processes are a key element of our Enterprise Risk Management (ERM) process, which is designed to identify and evaluate the full range of significant risks to RTX.
As part of our ERM program, RTX’s functional and operations departments identify and manage enterprise risks on an annual cycle.
−Removed: The process consists of structured reviews, discussions, and mitigation planning, and includes risks identified by our Enterprise Cybersecurity and Product Cybersecurity functions as part of the overall review of significant RTX risks.
−Removed: The top ERM risks are compiled
−Removed: annually and shared with the Audit Committee of the Board of Directors as well as the full Board of Directors.
+Added: The process consists of structured reviews, discussions, and mitigation planning, and includes risks identified by our Enterprise Cybersecurity and Product Cybersecurity functions as part of the overall review of significant risks to RTX.
+Added: The top ERM risks are compiled annually and shared with the Audit Committee of the Board of Directors as well as the full Board of Directors.
In addition, Internal Audit incorporates these risks into its continuous risk assessment process and periodically audits specific ERM risks.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.