10 unchanged sentences
We have established an Incident Response Plan that defines and documents procedures for assessing, identifying, and managing a cybersecurity incident.
−Removed: This plan requires the IT Security Manager to determine whether a cybersecurity incident has occurred and to communicate such findings to the Incident Response Team.
−Removed: The IT Security Manager is responsible for communicating incidents to the Vice President - IT and the other members of management as appropriate.
+Added: This plan requires the IT Security Director to determine whether a cybersecurity incident has occurred and to communicate such findings to the Incident Response Team.
+Added: The IT Security Director is responsible for communicating incidents to the Vice President - IT and the other members of management as appropriate.
If a cybersecurity incident is determined to be material by our management team, they would notify the Board .
−Removed: Our Vice President - IT and IT Security manager have developed expertise in cybersecurity, data protection, compliance, enterprise architecture and design, data analytics, and digital transformation through years of experience in the information technology space.
+Added: Our Vice President - IT and IT Security Director have developed expertise in cybersecurity, data protection, compliance, enterprise architecture and design, data analytics, and digital transformation through years of experience in the information technology space.
Our Vice President - IT is designated as the senior executive responsible for cybersecurity and reports directly to our CFO.
−Removed: She and the IT Security manager have comprehensive information technology background with over 30 years of information technology experience.
+Added: She and the IT Security Director have comprehensive information technology background with over 30 years of information technology experience.
These individuals are responsible for the day-to-day implementation of our cybersecurity program.
4 unchanged sentences
The Audit Committee is responsible for the oversight of risks from cybersecurity threats.
−Removed: Our Vice President - IT and the IT security team update the Audit Committee on our cyber risk management program during each of its quarterly meetings.
+Added: Our Vice President - IT and the IT security Director update the Audit Committee on our cyber risk management program during each of its quarterly meetings.
This update includes metrics on the effectiveness of technical and human security controls, cybersecurity training program compliance, internal and third-party cybersecurity incidents, and cybersecurity risks.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.