1 unchanged sentence
CYBERSECURITY
−Removed: Risk management and strategy
−Removed: We are in the process of implementing
−Removed: various information security procedures designed to identify, assess and manage material risks from cybersecurity threats to our critical
−Removed: computer networks, third party hosted services, communications systems, hardware and software, and our critical data, including intellectual
−Removed: property, confidential information that is proprietary, strategic or competitive in nature.
−Removed: Our Chief Information Officer,
−Removed: Chief Legal Officer, Chief Executive Officer, Chief Financial Officer and Chief Administrative Officer help identify, assess and manage
−Removed: the Company’s cybersecurity threats and risks.
−Removed: They will identify and assess risks from cybersecurity threats by monitoring and
−Removed: evaluating our threat environment using various methods including, for example manual and automated tools, subscribing to reports and
−Removed: services that identify cybersecurity threats, conducting scans of the threat environment, evaluating threats reported to us, internal
−Removed: and external audits, conducting threat assessments for internal and external threats, third-party threat assessments and conducting vulnerability
−Removed: assessments to identify vulnerabilities.
−Removed: Depending on the environment,
−Removed: we are in the process of implementing various technical, physical, and organizational measures, processes, standards and policies designed
−Removed: to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data, including, for example:
−Removed: response plan, incident detection, vulnerability management policy, network security controls, access controls, physical controls, systems
−Removed: monitoring, vendor risk management program, employee training, penetration testing, systems monitoring.
−Removed: Our assessment and management
−Removed: of material risks from cybersecurity threats will be integrated into the Company’s overall risk management processes.
−Removed: our Information Security Management committee will evaluate material risks from cybersecurity threats against our overall business objectives
−Removed: and report to the audit committee of the board of directors, which evaluates our overall enterprise risk.
−Removed: We use third-party service
−Removed: providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats, including for example,
−Removed: professional services firms, including legal counsel, cybersecurity consultants, cybersecurity software providers and penetration testing
−Removed: We use third-party service
−Removed: providers to perform a variety of functions throughout our business, such as application providers and hosting companies.
−Removed: For a description of the risks
−Removed: from cybersecurity threats that may materially affect the Company and how they may do so, see our risk factors under Part I.
−Removed: Risk Factors in this Annual Report on Form 10-K, including “Any unauthorized access to or disclosure or theft of personal information
−Removed: we gather, store or use could harm our reputation and subject us to claims or litigation.”
−Removed: The Audit Committee assists
−Removed: our board of directors in addressing the Company’s cybersecurity risk management as part of its general oversight function.
−Removed: board of directors’ Audit Committee is responsible for overseeing Company’s cybersecurity risk management processes, including
+Added: management and strategy
+Added: are in the process of implementing various information security procedures designed to identify, assess and manage material risks from
+Added: cybersecurity threats to our critical computer networks, third party hosted services, communications systems, hardware and software,
+Added: and our critical data, including intellectual property, confidential information that is proprietary, strategic or competitive in nature.
+Added: Senior Vice President of IT, Chief Legal Officer, and Chief Financial Officer help identify, assess and manage the Company’s cybersecurity
+Added: threats and risks.
+Added: They will identify and assess risks from cybersecurity threats by monitoring and evaluating our threat environment
+Added: using various methods including, for example manual and automated tools, subscribing to reports and services that identify cybersecurity
+Added: threats, conducting scans of the threat environment, evaluating threats reported to us, internal and external audits, conducting threat
+Added: assessments for internal and external threats, third-party threat assessments and conducting vulnerability assessments to identify vulnerabilities.
+Added: on the environment, we are in the process of implementing various technical, physical, and organizational measures, processes, standards
+Added: and policies designed to manage and mitigate material risks from cybersecurity threats to our Information Systems and Data, including,
+Added: incident response plan, incident detection, vulnerability management policy, network security controls, access controls,
+Added: physical controls, systems monitoring, vendor risk management program, employee training, penetration testing, and systems monitoring.
+Added: assessment and management of material risks from cybersecurity threats will be integrated into the Company’s overall risk management
+Added: For example, our Information Security Management committee will evaluate material risks from cybersecurity threats against
+Added: our overall business objectives and report to the Audit Committee of our Board of Directors, which evaluates our overall enterprise risk.
+Added: use third-party service providers to assist us from time to time to identify, assess, and manage material risks from cybersecurity threats,
+Added: including for example, professional services firms, including legal counsel, cybersecurity consultants, cybersecurity software providers
+Added: and penetration testing firms.
+Added: use third-party service providers to perform a variety of functions throughout our business, such as application providers and hosting
+Added: a description of the risks from cybersecurity threats that may materially affect the Company and how they may do so, see our risk factors
+Added: under Part I.
+Added: Risk Factors in this Annual Report on Form 10-K, including “Any unauthorized access to or disclosure
+Added: or theft of personal information we gather, store or use could harm our reputation and subject us to claims or litigation.”
+Added: Audit Committee assists our Board of Directors in addressing the Company’s cybersecurity risk management as part of its general
+Added: oversight function.
+Added: The Audit Committee is responsible for overseeing Company’s cybersecurity risk management processes, including
oversight of mitigation of risks from cybersecurity threats.
−Removed: The Audit Committee regularly reviews and discusses the Company’s cybersecurity
−Removed: risks with management, including the Company’s Chief Information Officer, General Counsel, Vice President of Human Resources and
−Removed: Vice President of Operations.
−Removed: Our Vice President of Information
−Removed: Technology is responsible for hiring appropriate personnel, helping to integrate cybersecurity risk considerations into the Company’s
−Removed: overall risk management strategy, and communicating key priorities to relevant personnel.
−Removed: The Chief Financial Officer is responsible for
−Removed: approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security assessments
−Removed: and other security-related reports.
−Removed: Our cybersecurity incident
−Removed: response policy is being designed to escalate certain cybersecurity incidents to members of management depending on the circumstances.
−Removed: The Company’s Chief Executive Officer and Chief Information Officer work to help the Company mitigate and remediate cybersecurity
+Added: The Audit Committee regularly reviews and discusses the Company’s
+Added: cybersecurity risks with management, including the Company’s Chief Executive Officer, Chief Administrative Officer, Chief Financial
+Added: Officer, Chief Legal Officer, and other applicable leaders.
+Added: Senior Vice President of IT is responsible for hiring appropriate personnel, helping to integrate cybersecurity risk considerations into
+Added: the Company’s overall risk management strategy, and communicating key priorities to relevant personnel.
+Added: The Chief Financial Officer
+Added: is responsible for approving budgets, helping prepare for cybersecurity incidents, approving cybersecurity processes, and reviewing security
+Added: assessments and other security-related reports.
+Added: cybersecurity incident response policy is being designed to escalate certain cybersecurity incidents to members of management depending
+Added: on the circumstances.
+Added: The Company’s Senior Vice President of IT works to help the Company mitigate and remediate cybersecurity
incidents of which they are notified.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.