12 unchanged sentences
Such provisions relate to the handling of information and computers, as well as the protection of computer systems and software from unauthorized persons .
+Added: USCF engages a third-party consultant and service provider to assist with information technology services and advise on USCF’s information technology infrastructure.
As needed, but no less frequently than annually, USCF evaluates its cybersecurity risk profile in accordance with its compliance policies and procedures.
−Removed: The risk assessment aims to confirm that USCF's policies are being followed and enforced, and to identify risks that may have otherwise been unknown.
−Removed: To mitigate the risk from third parties, USCF conducts due diligence on its critical third-party service providers with respect to (1) the cybersecurity programs and policies that they have in place as well as how they safeguard sensitive information, and (2) how those programs and policies apply to customers, including USCF and UNL.
+Added: To mitigate the risks from cybersecurity threats posed by third parties, USCF conducts due diligence on its critical third-party service providers with respect to (1) the cybersecurity programs and policies that they have in place as well as how they safeguard sensitive information, and (2) how those programs and policies apply to customers, including USCF and UNL.
USCF’s procedures include guidance for determining the materiality of cybersecurity incidents, including with respect to cybersecurity incidents experienced by third-party service providers.
3 unchanged sentences
The Director of Compliance , as identified below, provides regular reports to USCF’s Board of Directors on developments to the information security and cybersecurity risks facing UNL.
−Removed: Reports will include, among other things, an overview of the controls and procedures related to assessing, identifying, and managing risks related to cybersecurity threats, oversight of third-party service providers and related cybersecurity threats, and management's evaluation of cybersecurity risks material to UNL.
+Added: Reports may include, among other things, an overview of the controls and procedures related to assessing, identifying, and managing risks related to cybersecurity threats, oversight of third-party service providers and related cybersecurity threats, and management’s evaluation of cybersecurity risks material to UNL.
Not applicable.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.