5 unchanged sentences
Our Information Security Officer is primarily responsible for this cybersecurity component and is a key member of the risk management organization, reporting directly to the Chief Risk Officer and, as discussed below, periodically to the Information Technology Steering Committee and our Board of Directors.
−Removed: Our objective for managing cybersecurity risk is to avoid or minimize the impacts of internal and external threat events or other efforts to penetrate, disrupt or misuse our systems or information.
−Removed: The structure of our information security program is designed around the National Institute of Standards and Technology Cybersecurity Framework, Federal Financial Institution Examination Council Cybersecurity Assessment Tool, regulatory guidance, and other industry standards.
+Added: Our objective for managing cybersecurity risk is to avoid or minimize the impacts of external threat events or other efforts to penetrate, disrupt or misuse our systems or information.
+Added: The structure of our information security program is designed around the National Institute of Standards and Technology (“NIST”) Cybersecurity Framework, Federal Financial Institution Examination Council (“FFIEC”) Cybersecurity Assessment Tool, regulatory guidance, and other industry standards.
In addition, we leverage certain industry and government associations, third-party benchmarking, audits, and threat intelligence feeds to facilitate and promote program effectiveness.
−Removed: Our Information Security Officer and our Chief Information and Operations Officer, along with key members of their teams, regularly collaborate with peer banks, industry groups, and policymakers to discuss cybersecurity trends and issues and identify best practices.
+Added: Our Information Security Officer and our Chief Information and Operations Officer, along with key members of his team, regularly collaborate with peer banks, industry groups, and policymakers to discuss cybersecurity trends and issues and identify best practices.
The Information Security Program is periodically reviewed by such personnel with the goal of addressing changing threats and conditions and maturing our Information Security Program.
1 unchanged sentence
We leverage people, processes, and technology as part of our efforts to manage and maintain cybersecurity controls.
−Removed: We also employ a variety of tools and processes to identify, protect against, detect, respond, recover from, and govern cybersecurity risks and threats.
+Added: We also employ a variety of tools and processes to identify, protect against, detect, respond, recover from, and govern the cybersecurity risks and threats.
We have tools configured to block, prevent, detect, and monitor for suspicious activity providing real time monitoring and alerts for anomalous and nefarious activity, as well as advanced persistent threats.
We engage in regular assessments of our infrastructure, software systems, and network architecture, using internal cybersecurity experts and third-party specialists.
−Removed: We maintain a third-party risk management program designed to identify, assess, and manage risks, including cybersecurity risks, associated with external service providers and our supply chain.
−Removed: We actively monitor our email traffic for malicious phishing email campaigns, provide ongoing training for employees to help them detect possible malicious emails and monitor remote connections.
+Added: We also maintain a third-party risk management program designed to identify, assess, and manage risks, including cybersecurity risks, associated with third parties, external service providers and our supply chain.
+Added: We also actively monitor our email traffic for malicious phishing email campaigns and monitor remote connections as a significant portion of our workforce has the option to work remotely.
We leverage internal and external auditors and independent external partners to periodically review our processes, systems, and controls, including with respect to our information security program, to assess their design and operating effectiveness and make recommendations to strengthen our risk management program.
1 unchanged sentence
The Incident Response Plan is coordinated through the Information Security Officer.
−Removed: Key members of management are embedded into the Plan by its design.
+Added: Key members of management are embedded into the Incident Response Plan by its design.
The Incident Response Plan facilitates coordination across multiple parts of our organization and is evaluated at least annually.
1 unchanged sentence
Our internal systems, processes, and controls are designed to mitigate loss from cyber-attacks and, while we have experienced cybersecurity incidents in the past, to date, risks from cybersecurity threats have not materially affected our company.
+Added: For further discussion of risks from cybersecurity threats, see the section captioned “Our Information Systems May Experience Failure, Interruption or Breach In Security” in Item 1A.
+Added: Risk Factors.
Our Information Security Officer is accountable for overseeing and directing our Information Security Program.
4 unchanged sentences
Individuals within the department are generally subject to professional education and certification requirements.
−Removed: In particular, our Information Security Officer has over ten years of information security experience and four cybersecurity related certifications.
+Added: In particular, our Information Security Officer has over 20 years of information security experience in the Banking, Government, Military, Energy, and Insurance sectors and has the following cybersecurity certifications:
+Added: Certified Information Systems Security Professional (CISSP), BS in Information Systems with a focus in Cyber Security, CompTIA Security+, CCNA (Security), CCNA (Route/Switch), CCNA (Collaboration), CompTIA Net+, Microsoft Certified System Engineer MCSE (win2000).
Our Board of Directors has approved management committees including the Information Technology Steering Committee, which focuses on technology impact, and the Risk Management Committee, which focuses on business impact.
2 unchanged sentences
More frequent meetings occur from time to time in accordance with the Incident Response Plan in order to facilitate timely informing and monitoring efforts.
−Removed: The Information Security Officer reports summaries of key issues, including significant cybersecurity and/or privacy incidents, discussed at committee meetings and the actions taken to the Information Technology Steering Committee on a monthly basis (or more frequently as may be required by the Incident Response Plan).
+Added: The Information Security Officer informs the Information Technology Steering Committee by reporting on key issues, including significant cybersecurity and/or privacy incidents, discussed at committee meetings and the actions taken in response.
+Added: The Information Technology Steering Committee meets on a monthly basis (or more frequently as may be required by the Incident Response Plan).
The Information Technology Steering Committee is responsible for overseeing our information security and technology programs, including management’s actions to identify, assess, mitigate, and remediate or prevent material cybersecurity issues and risks.
3 unchanged sentences
The Information Technology Steering Committee and Risk Management Committee each provide a report of their activities to the full Board of Directors at each board meeting.
+Added: The principal individuals on the Information Technology Steering Committee responsible for the foregoing activities are the Chief Information and Operations Officer (Chairman of the Committee);
+Added: the Information Security Officer;
+Added: and the Chief Risk Officer.
+Added: The experience of Chief Information and Operations Officer;
+Added: Information Security Officer;
+Added: and Chief Risk Officer are as follows:
+Added: 35 years of experience in bank operations, systems development, payments, and information technology in Financial Services sector;
+Added: 20 years of information security experience in the Banking, Government, Military, Energy, and Insurance sectors;
+Added: and 29 years of experience in audit and risk management in the Financial Services Sector (banking) as an FDIC Examiner;
+Added: Internal Audit Director;
+Added: and Chief Risk Officer, respectively.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.