4 unchanged sentences
Our cybersecurity policies, standards and practices follow recognized frameworks established by the National Institute of Standards and Technology, the International Organization for Standardization and other applicable industry standards.
−Removed: We generally approaches cybersecurity threats through a cross-functional, multilayered approach, with specific the goals of:
+Added: We generally approach cybersecurity threats through a cross-functional, multilayered methodology, with specific the goals of:
(i) identifying, preventing and mitigating cybersecurity threats to us;
4 unchanged sentences
Risk Management and Strategy
−Removed: Consistent with overall ERM policies and practices, the Company’s cybersecurity program focuses on the following areas:
+Added: Consistent with overall ERM policies and practices, our cybersecurity program focuses on the following areas:
we maintain cybersecurity threat operations with the specific goal of identifying, preventing and mitigating cybersecurity threats and responding to cybersecurity incidents in accordance with our established incident response plans;
3 unchanged sentences
we provide periodic training and education for personnel regarding cybersecurity threats, which reinforces our information security policies, standards and practices, and such training is scaled to reflect the roles, responsibilities and information systems access of such personnel;
−Removed: we have established and maintain comprehensive incident response plans that fully address our response to a cybersecurity incident and the recovery from a cybersecurity incident, and such plans are evaluated on an regular basis;
+Added: we have established and maintain comprehensive incident response plans that fully outlines our response to, and recovery from a cybersecurity incident and the recovery from a cybersecurity incident, and such plans are evaluated on an regular basis;
we utilize a cross-functional approach to address the risk from cybersecurity threats, involving management personnel from our technology, operations, legal, finance and other key business functions, as well as the members of the Board and the Audit Committee in an ongoing dialogue regarding cybersecurity threats and incidents, while also implementing controls and procedures for the escalation of cybersecurity incidents pursuant to established thresholds so that decisions regarding the disclosure and reporting of such incidents can be made by management in a timely manner;
2 unchanged sentences
The Board and the Audit Committee each participate in relevant discussions on cybersecurity risks, which address a wide range of topics including, for example, recent developments, evolving standards, vulnerability assessments, the threat environment, technological trends and information security considerations arising with respect to our peers and third parties.
−Removed: The Board and the Audit Committee would also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding such incident until it has been addressed, to the extent applicable.
+Added: The Board and the Audit Committee will also receive prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding such incident until it has been addressed, to the extent applicable.
Our Director of Information Technology is principally responsible for overseeing our cybersecurity risk management program, in partnership with other members of our management team.
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.