2 unchanged sentences
Risk Management and Strategy
−Removed: As SandRidge has increasingly relied on information technology systems and networks in connection with our business activities, we recognize the critical importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data.
+Added: As SandRidge has increasingly relied on information technology ("IT") systems and networks in connection with our business activities, we recognize the critical importance of developing, implementing, and maintaining robust cybersecurity measures to safeguard our information systems and protect the confidentiality, integrity, and availability of our data.
SandRidge has strategically integrated cybersecurity risk management into our broader risk management framework to promote a company-wide culture of cybersecurity risk management.
26 unchanged sentences
Governance – Board Oversight and the Role of Management
−Removed: The Board of Directors is acutely aware of the critical nature of managing risks associated with cybersecurity threats.
+Added: The Board is acutely aware of the critical nature of managing risks associated with cybersecurity threats.
The Board has established robust oversight mechanisms to ensure effective governance in managing risks associated with cybersecurity threats because we recognize the significance of these threats to our operational integrity and stakeholder confidence.
2 unchanged sentences
Primary responsibility for assessing and integrating within enterprise risk management of our cybersecurity risks rests with our Director of Internal Audit , who oversees our governance programs, tests our compliance with standards, remediates known risks, and coordinates our employee training program.
−Removed: The Director of Internal Audit is a Certified Fraud Examiner with over 20 years of planning and managing information technology audits, including information technology general controls for SOX, and cybersecurity breach protocols, policies and assessments.
+Added: The Director of Internal Audit is a Certified Fraud Examiner with over 20 years of planning and managing information technology audits, including information technology general controls for the Sarbanes-Oxley Act ("SOX"), and cybersecurity breach protocols, policies and assessments.
The Director of Internal Audit, in their capacity, regularly informs the Chief Executive Officer (“CEO”), the Chair of the Audit Committee, and other members of management of aspects related to cybersecurity risks and incidents.
This ensures that the appropriate levels of management are kept abreast of the cybersecurity posture and potential risks facing SandRidge.
−Removed: Furthermore, significant cybersecurity matters, and strategic risk management decisions are escalated to the Board of Directors, ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues.
+Added: Furthermore, significant cybersecurity matters, and strategic risk management decisions are escalated to the Board, ensuring that they have comprehensive oversight and can provide guidance on critical cybersecurity issues.
Information regarding the Company’s properties is included in Item 1.
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.