4 unchanged sentences
These processes are designed to protect our information technology and operational systems against cybersecurity threats.
−Removed: In connection with the operation of our program, we take into consideration guidance from various recognized cybersecurity industry frameworks and standards such as the National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”) and the International Organization for Standardization (“ISO”) 27001 standards.
−Removed: This does not mean that we adhere to any particular frameworks or meet any particular standards, but rather that we use industry frameworks and standards as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
−Removed: Information about cybersecurity risk is collected as part of our overall enterprise risk management program, including as part of the annual enterprise risk assessment survey conducted by our internal audit team, the results of which are summarized and provided to our Audit Committee.
+Added: In connection with the operation of our program, we take into consideration guidance from various recognized cybersecurity industry frameworks and standards such as the National Institute of Standards and Technology Cybersecurity Framework (“NIST”) and the International Organization for Standardization (“ISO”) 27001 standards.
+Added: We are certified and externally audited to ISO / IEC 27001:2022.
+Added: We leverage a controls framework, based on these industry frameworks and standards, as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
+Added: Information about cybersecurity risk is collected as part of our annual cybersecurity risk assessment and overall enterprise risk management program, including as part of the annual enterprise risk assessment survey conducted by our internal audit team, the results of which are summarized and provided to our Audit Committee.
We devote significant resources and efforts to protecting the security of our information technology and operational systems, including utilizing threat monitoring and commissioning assessments by third parties, taking guidance from ISO information security standards, and conducting proactive risk and compliance reviews against regulatory, industry, and evolving data privacy requirements.
−Removed: We provide training to our employees on our acceptable use policy, our data protection methods, and social engineering tactics used by threat actors, including through simulated phishing attacks.
+Added: We provide ongoing cybersecurity training to our employees based on access to our network and roles, which includes annual training to non-factory employees on our acceptable use policy, our data protection methods, and social engineering tactics used by threat actors.
We maintain a cross-functional cybersecurity incident management procedure with defined roles, responsibilities, and reporting protocols that is designed to timely respond to, investigate, mitigate, remediate, and if appropriate, disclose, a cybersecurity incident.
8 unchanged sentences
In this role, the Audit Committee receives quarterly updates from members of management, including the vice president, information technology and CIO, who oversees our information technology function (“CIO”) and another vice president who supports the CIO in implementing, monitoring and updating the cybersecurity risk management program, as well as addressing existing and emerging cybersecurity threats and managing cybersecurity incidents (“Head of Information Security”).
−Removed: The Board receives regular reports from the Audit Committee, as well as an annual cybersecurity report from management, including the CIO, highlighting key activities of the Company’s cybersecurity team, including internal initiatives and updates and external engagements with third party cybersecurity firms, recent incidents throughout the industry and the emerging threat landscape.
+Added: The Board receives regular reports from the Audit Committee, as well as an annual cybersecurity report or materials from management, including the CIO, highlighting key activities of the Company’s cybersecurity team, including internal initiatives and updates and external engagements with third party cybersecurity firms, recent incidents throughout the industry and the emerging threat landscape.
Our CIO has more than 25 years of experience in information technology and reports to our Chief Financial Officer.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.