UNRESOLVED STAFF COMMENTS
−Removed: CYBER SECURITY
+Added: CYBERSECURITY
Risk Management and Strategy
13 unchanged sentences
The Company engages third parties to evaluate certain aspects of the ISMS, provide threat intelligence, and perform vulnerability assessments and other services as needed.
−Removed: The Company follows an established process to identify and evaluate risks from cyber security threats that may arise internally or through the introduction of third parties to the ISMS.
+Added: The Company follows an established process to identify and evaluate risks from cybersecurity threats that may arise internally or through the introduction of third parties to the ISMS.
This evaluation is part of the Company's risk management process.
5 unchanged sentences
In the event of an incident, we follow our IRP, which includes evaluation of the severity of the incident based on factors such as the number of assets affected, the extent of the incident, the likelihood of inappropriate data exposure, operational impact and/or reliability impact.
−Removed: Dependent upon the severity of an incident, the incident is escalated to the senior leadership, including the CEO and CISO.
+Added: Dependent upon the severity of an incident, the incident is escalated to the senior leadership, including the CEO and senior leadership.
Senior leadership then determines whether, based on various factors, the incident requires immediate escalation to the Board of Directors and to third -party incident response organizations and notification to functional areas, such as legal and finance, as well as senior leadership and the Board, and external entities, as appropriate and required.
2 unchanged sentences
For a detailed description of the risks related to cybersecurity, see Item 1A.
−Removed: “Risk Factors.” of this Form 10-K, which should be read in conjunction with this Item 1C.
+Added: “Risk Factors.” of this Annual Report, which should be read in conjunction with this Item 1C.
Board Governance and Management
The Board of Directors oversees management’s processes for identifying and mitigating risks, including cybersecurity risks, to help align our risk exposure with our strategic objectives.
−Removed: Our corporate information security function, led by our Chief Information Security Officer (“CISO”), is responsible for our overall information security strategy, policy, security engineering, operations and cyber threat detection and response.
−Removed: The current CISO has an extensive information technology and cybersecurity background gained through years of industry experience and leadership.
+Added: Senior leadership manages our overall information security strategy, policy, security engineering, operations and cyber threat detection and response.
The corporate information security function is responsible for managing and continually enhancing our information security posture and information security infrastructure with the ultimate goal of preventing cybersecurity incidents and reducing their severity to the extent feasible, while simultaneously increasing our resilience in an effort to minimize the business impact should an incident occur.
−Removed: Senior leadership, including our CEO, who also has relevant experience in cybersecurity matters, and our CISO, regularly brief the Board of Directors on our cybersecurity and information security initiatives, and the Board of Directors is apprised of cybersecurity incidents deemed to have a material business impact.
+Added: Senior leadership, including our CEO, who also has relevant experience in cybersecurity matters, regularly brief the Board of Directors on our cybersecurity and information security initiatives, and the Board of Directors is apprised of cybersecurity incidents deemed to have a material business impact.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.