5 unchanged sentences
Despite this, there can be no guarantee that our policies and procedures will be effective.
−Removed: Refer to “ Risk Factors ” for additional detail about the material cybersecurity risks we face.
+Added: Refer to “ Risk Factors ” for additional detail about the material cybersecurity risks that could affect our business strategy, results of operations, or financial condition, including under the heading “If we are unable to protect our information systems and networks against data corruption, cyber-based attacks or network security breaches, our operations could be disrupted”.
Our cybersecurity program includes the following:
9 unchanged sentences
We regularly assess and deploy technical safeguards based on vulnerability assessments, cybersecurity threat intelligence and incident response experience.
−Removed: In addition, our third-party technology service providers are contractually obligated to maintain cybersecurity controls and complete our security questionnaires at the time of onboarding.
−Removed: On a recurring basis, our third-party service providers are required to update their responses to our security questionnaires and, where available, additional information such as System and Organization Controls (“SOC”) SOC 1 or SOC 2 reports are provided.
+Added: In addition, our third-party technology service providers are contractually obligated to maintain cybersecurity controls and provide System and Organization Controls (“SOC”) SOC 2 reports, ISO 27001 certifications or complete our security questionnaires at the time of onboarding.
+Added: On a recurring basis, our material third-party service providers are required to update their responses to our security questionnaires or provide updated reports as noted above.
Board and Management Oversight
3 unchanged sentences
Our CIO holds an undergraduate degree in computer science.
−Removed: Our CISO holds 11 industry security, risk, and/or privacy certifications and has served in various roles in information technology and information security for 25 years, including serving as the Director, Global Security, Privacy & Data Governance for one of the world's largest privately held transport corporations.
+Added: Our CISO holds 11 industry security, risk, and/or privacy certifications and has served in various roles in information technology and information security for over 25 years, including serving as the Director, Global Security, Privacy & Data Governance for one of the world's largest privately held transport corporations.
Our Board, in coordination with the Audit Committee, oversees our management of cybersecurity risk.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.