12 unchanged sentences
We maintain and continue to expand our investment in the development of our information security management system (“ISMS”).
−Removed: Our ISMS leverages a risk-based approach and is informed by industry standard guidance, including the National Institute of Standards and Technology ("NIST”) Cybersecurity Framework (“CSF”) and the International Organization for Standardization (“ISO”) 27001 Information Security Management System Requirements.
+Added: Our ISMS leverages a risk-based approach and is informed by industry standard guidance, including the National Institute of Standards and Technology, Cybersecurity Framework, and the International Organization for Standardization 27001 Information Security Management System Requirements.
A material cyber-attack on Company systems, distribution partners and their key operating systems, or any other third -party partners or vendors and their key operating systems may interrupt the ability to operate the Company's business, damage the Company's reputation, or result in monetary damages.
9 unchanged sentences
In the event of an incident, we follow our IRP, which includes evaluation of the severity of the incident based on factors such as the number of assets affected, the extent of the incident, the likelihood of inappropriate data exposure, operational impact and/or reliability impact.
−Removed: Dependent upon the severity of an incident, the incident is escalated to the senior leadership, including the CEO and senior leadership.
−Removed: Senior leadership then determines whether, based on various factors, the incident requires immediate escalation to the Board of Directors and to third -party incident response organizations and notification to functional areas, such as legal and finance, as well as senior leadership and the Board, and external entities, as appropriate and required.
+Added: Depending upon the severity of an incident, the incident is escalated to the senior leadership, including the CEO.
+Added: Senior leadership then determines whether, based on various factors, the incident requires immediate escalation to the Board of Directors and to third -party incident response organizations and notification to functional areas, such as legal and finance, as well internal stakeholders, and external entities, as appropriate and required.
We maintain relationships with third -party Digital Forensics and Incident Response (“DFIR”) service providers to strengthen our incident response capabilities in the event that we determine the need to augment our effort during an incident and to provide us additional assurance that our responses to complex incidents or highly sophisticated threat actors have been effective and complete.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.