8 unchanged sentences
Our cybersecurity program is predicated on the National Institute of Standards and Technology Cybersecurity Framework (NIST CSF).
−Removed: At minimum, on an annual basis we measure ourselves against this framework and use the NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our strategic execution.
−Removed: W e have also implemented a third-party risk assessment process for certain service providers, suppliers, and vendors, which is conducted during the procurement cycle.
−Removed: Critical vendors are assessed on an annual basis.
+Added: At a minimum, on an annual basis we measure ourselves against this framework and use the NIST CSF as a guide to help us identify, assess, and manage cybersecurity risks relevant to our strategic execution.
+Added: We also have implemented a third-party risk assessment process for certain service providers, suppliers, and vendors, which is conducted during the procurement cycle and, with respect to critical vendors on an annual basis.
In addition, all team members are required to participate in ongoing training and awareness programs that include periodic assessments to drive adoption and awareness of cybersecurity processes and controls.
1 unchanged sentence
As part of our cybersecurity risk management strategy, our corporate information technology team collaborates cross-functionally with key business leaders within privacy, compliance, finance and operations, among others, to identify, assess, and manage cybersecurity risks relevant to our business.
−Removed: On a quarterly basis, led by the Chief Information Security Officer (CISO) and Privacy Officer, the cybersecurity and privacy governance committee meets, which comprises of our executive and regional leadership teams.
−Removed: This governance committee assists in discussing existing or emerging threats, prioritizing roadmap items and/or budgetary considerations for project work.
+Added: Additionally, we have a cybersecurity and privacy governance committee, consisting of our executive and regional leadership teams and led by our Chief Information Security Officer (CISO) and Privacy Officer, which meets on a quarterly basis.
+Added: This committee assists in discussing existing or emerging threats, prioritizing roadmap items and/or budgetary considerations for project work.
No risks from cybersecurity threats or previous cybersecurity incidents have materially affected, or are reasonably likely to materially affect, our business strategy, financial condition or results of operations.
−Removed: However, there can be no assurance that the controls and procedures in place to monitor and mitigate the risks of cyber threats will be successful or sufficient to avoid material losses or consequences in the future.
−Removed: Additionally, while we have insurance coverage in place that is designed to address certain aspects of cyber risks, such insurance coverage may be insufficient to cover all insured losses or all types of claims that may arise.
+Added: However, there can be no assurance that the controls and procedures in place to monitor and mitigate the risks of cybersecurity threats will be successful or sufficient to avoid material losses or consequences in the future.
+Added: Additionally, while we have insurance coverage in place that is designed to address certain aspects of cybersecurity risks, such insurance coverage may be insufficient to cover all insured losses or all types of claims that may arise.
Cybersecurity Governance
4 unchanged sentences
Our cybersecurity team is led by our CISO , who has over 20 years of experience in the cybersecurity space and is a Certified Information Security Manager (CISM).
−Removed: On an annual basis, at a minimum, our CISO or Chief Information Officer (CIO) present necessary updates on our cybersecurity risks and any material cybersecurity incidents.
+Added: On an annual basis, at a minimum, our CISO or Chief Information Officer (CIO) present necessary updates on our cybersecurity risks and any material cybersecurity incidents to the Audit Committee of the Board.
These updates include the following:
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.