8 unchanged sentences
Sandisk’s Information Security organization addresses cybersecurity risks with a broad spectrum of technologies, controls, and processes that focus on mitigating these risks.
−Removed: Our cybersecurity strategy is designed to be dynamic and adaptive to combat the rapidly-evolving cybersecurity threat landscape and is influenced by commonly leveraged frameworks such as the NIST-CSF (National Institute of Standard and Technologies – Cyber Security Framework).
+Added: Our cybersecurity strategy is designed to be dynamic and adaptive to combat the rapidly-evolving cybersecurity threat landscape and is influenced by commonly leveraged frameworks such as the NIST-CSF (National Institute of Standards and Technology – Cybersecurity Framework).
Our program includes, but is not limited to, endpoint protection and response systems, network security protocols, electronic communications protections, vulnerability management programs, least-privilege access controls, third-party risk management procedures, workforce education and training exercises, and compliance programs.
−Removed: Our dedicated 24x7 Security Operations Center incorporates specialized systems and processes for handling security incidents into its regular work and operates a robust, modern security infrastructure with appropriate security sensors and event monitoring capabilities.
+Added: Our dedicated 24x7 Security Operations Center incorporates specialized systems and processes for handling cybersecurity incidents into its regular work and operates a robust, modern security infrastructure with appropriate security sensors and event monitoring capabilities.
Upon detection of a cybersecurity incident, the Security Operations Center determines the severity of the incident in accordance with a pre-established incident severity matrix, initiates the appropriate notification and escalation protocols and begins triage.
Predefined severity tiers serve as a guide to match our response to each incident’s determined severity or risk level.
−Removed: Additionally, we have established a Cyber Incident Response Plan that follows the structure of the Incident Handling Guide published by the U.S.
+Added: Additionally, we have established a Cybersecurity Incident Response Plan that follows the structure of the Incident Handling Guide published by the U.S.
National Institute of Standards and Technology (SP 800-61r3) and that serves as an operational guide for handling cybersecurity incidents at Sandisk.
−Removed: Our Cyber Incident Response Plan provides procedural and strategic guidance that is designed to be flexible enough to apply to a variety of different incidents, but also specific enough to provide guidelines for incident prevention, detection, analysis, escalation and notification, and containment, eradication and recovery.
−Removed: As part of our ongoing information security program, the Company utilizes periodic independent third-party experts to conduct assessments of our program’s effectiveness.
+Added: Our Cybersecurity Incident Response Plan provides procedural and strategic guidance that is designed to be flexible enough to apply to a variety of different incidents, but also specific enough to provide guidelines for incident prevention, detection, analysis, escalation and notification, and containment, eradication and recovery.
+Added: As part of our ongoing information security program, the Company periodically utilizes independent third-party experts to conduct assessments of our program’s effectiveness.
These experts are also leveraged to design and orchestrate tabletop exercises where multiple business functions and leadership levels navigate incident scenarios based on industry trends and relevant threats, to help determine our level of preparedness for various cybersecurity incidents.
4 unchanged sentences
However, we can give no assurance that we have detected or protected against all such cybersecurity incidents or threats or that we will not experience such an incident in the future.
−Removed: Further details about the cybersecurity risks we face are described under “The compromise, damage or interruption of our technology infrastructure, information systems or products by cybersecurity incidents, data security breaches, other security problems, design defects, information system failures or other events could have a material negative impact on our business” in Part I, Item 1A., Risk Factors of this Annual Report on Form 10-K.
+Added: Further details about the cybersecurity risks we face are described under “The compromise, damage or interruption of our technology infrastructure, systems or products by cybersecurity incidents, data security breaches, other security problems, design defects or system failures could have a material negative impact on our business” in Part I, Item 1A., Risk Factors of this Annual Report on Form 10-K.
The Company has implemented a governance framework related to cybersecurity that includes operational risk-mitigation practices and Board-level cybersecurity risk oversight.
−Removed: Our management team is charged with managing cybersecurity risk and identifying material cybersecurity risk exposures to our company and carries out this function primarily through our Information Security organization, which is led by our Chief Information Security Officer (“CISO”) who has a CISO executive certification from the Heinz College at Carnegie Mellon University, a bachelor’s degree in Electrical Engineering, over a decade of information security leadership, and over twenty years of consolidated IT leadership experience.
−Removed: Additionally, our Cyber Incident Response Plan discussed above calls for the establishment of a management Impact Assessment Committee, which consists of key leadership representatives from the organization and is convened on an ad hoc basis to assess the detailed business impact of a cybersecurity incident.
−Removed: The Impact Assessment Committee is led by our Chief Information Security Officer and includes key representatives from the Company’s functional groups, including human resources, ethics and compliance, labor, privacy, internal audit, finance, communications, legal, risk and accounting.
−Removed: The Impact Assessment Committee receives updates and communications from the Security Operations Center on a fixed cadence determined by incident severity and follows our pre-established escalation framework to communicate with and include executive leadership, outside counsel and the Board of Directors, as appropriate.
+Added: Our management team is charged with managing cybersecurity risk and identifying material cybersecurity risk exposures to our company and carries out this function primarily through our Information Security organization, which is led by our Chief Information Security Officer (“CISO”) who has over 25 years of experience managing global information technology and cybersecurity operations, having served in executive roles up to Chief Information Officer, and holding multiple industry-recognized certifications such as Certified Information Systems Security Professional and Certificate of Cloud Security Knowledge, as well as a certificate from the Stanford Advanced Cybersecurity Program.
+Added: Our CISO reports to our Chief Information Officer, who has more than 25 years of experience in information technology.
+Added: Additionally, our Cybersecurity Incident Response Plan discussed above calls for the establishment of an Impact Assessment Committee, which consists of members of executive leadership and is convened on an ad hoc basis to assess the detailed business impact of a cybersecurity incident.
+Added: The Impact Assessment Committee is led by our Chief Information Security Officer and includes members of the executive leadership team.
+Added: During a cybersecurity incident, the Impact Assessment Committee receives incident updates to support strategic decision-making regarding the Company’s response, with a focus on prioritizing safe, secure, and efficient business continuity or restoration of services, as appropriate.
The Impact Assessment Committee works with the Company’s internal and external legal counsel to determine and facilitate appropriate communications with the Board of Directors.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.