19 unchanged sentences
In addition, we strive to meet all security requirements mandated by government and commercial customers and adhere to regulatory guidance and standards for system security engineering.
−Removed: Many of our products also undergo industry audits and regulatory compliance certifications, and our products delivered to the Department of Defense (DoD) must comply with DoD risk management requirements.
+Added: Many of our products also undergo industry audits and regulatory compliance certifications, and our products delivered to the U.S.
+Added: Department of War (DoW) (formerly referred to as the U.S.
+Added: Department of Defense) must comply with DoW risk management requirements.
Cybersecurity for Systems used in Support of U.S.
23 unchanged sentences
Our cybersecurity program is regularly assessed through management self-evaluation and ongoing monitoring procedures to evaluate our program effectiveness, including assessments associated with internal controls over financial reporting as well as vulnerability management through active discovery and testing to validate patching and configuration.
−Removed: Additionally, our Internal Audit function regularly assesses our program effectiveness through audits of our systems and processes to help maintain compliance with policies.
+Added: Additionally, our Internal Audit function regularly assesses our program effectiveness through audits of our systems and processes to help
+Added: maintain compliance with policies.
As cybersecurity threats are continuously evolving, we also periodically engage with third parties to perform maturity assessments of our program to identify potential risk areas and improvement opportunities.
1 unchanged sentence
We use these assessments to supplement our own evaluation of the overall health of our program and target improvement areas.
−Removed: Several external organizations also evaluate our enterprise cybersecurity program, including the Defense Contract Management Agency (DCMA) and Cybersecurity Maturity Model Certification Third-Party Assessment Organization.
−Removed: Moreover, some of our products are audited or reviewed for regulatory compliance certification pursuant to the relevant DoD risk management framework.
+Added: Several external organizations also evaluate our enterprise cybersecurity program, including the Defense Contract Management Agency (DCMA) and Cybersecurity Maturity Model Certification Third-Party Assessment Organizations.
+Added: Moreover, some of our products are audited or reviewed for regulatory compliance certification pursuant to the relevant DoW risk management framework.
Board Oversight and Management’s Role
14 unchanged sentences
Our PCO updates the Special Activities Committee on cybersecurity risks as they relate to our products and services, in addition to updates on product and service cybersecurity incidents, defenses, and mitigation strategies.
−Removed: Our PCO is an experienced embedded systems engineer and chief engineer with nearly 20 years’ experience in the development, product assurance, and security of critical and highly regulated embedded and other computer systems in medical, aviation, and military products and services.
+Added: Our PCO is an experienced embedded systems engineer and chief engineer with 20 years’ experience in the development, product assurance, and security of critical and highly regulated embedded and other computer systems in medical, aviation, and military products and services.
In performing her role, she regularly reviews cybersecurity risks, controls, program policy and processes, including training, and oversees and advises teams performing policy and program development, implementation, and updates.
9 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.