7 unchanged sentences
We utilize various risk assessment tools and technologies to identify potential cyber and information security threats and risks as well as engage with various third parties to assist in program development, risk evaluation and testing.
−Removed: For example, we have implemented a third-party risk assessment process for certain service providers, suppliers, and vendors, which is conducted during the procurement cycle.
+Added: Our cybersecurity program is predicated on the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF).
+Added: At minimum, on an annual basis we measure ourselves against this framework and use the NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our strategic execution.
+Added: W e have also implemented a third-party risk assessment process for certain service providers, suppliers, and vendors, which is conducted during the procurement cycle.
Critical vendors are assessed on an annual basis.
8 unchanged sentences
Cybersecurity Governance
−Removed: Management is responsible for the day-to-day handling of risks facing our Company Our Board of Directors, as a whole and through its committees, oversees risk management, including cybersecurity risks.
+Added: Management is responsible for the day-to-day handling of risks facing our Company.
+Added: Our Board of Directors as a whole and through its committees, oversees risk management, including cybersecurity risks.
The Board has delegated risk management responsibilities with respects to cybersecurity to our Audit Committee.
1 unchanged sentence
Our cybersecurity team is led by our CISO , who has over 20 years of experience in the cybersecurity space and is a Certified Information Security Manager (CISM).
−Removed: On an annual basis, at minimum, our CISO or Chief Information Officer (CIO) present necessary updates on our cybersecurity risks and any material cybersecurity incidents.
+Added: On an annual basis, at a minimum, our CISO or Chief Information Officer (CIO) present necessary updates on our cybersecurity risks and any material cybersecurity incidents.
These updates include the following:
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.