5 unchanged sentences
The Company maintains a global presence, with cybersecurity threat operations functioning 24/7 with the specific goal of identifying, preventing and mitigating cybersecurity threats and responding to cybersecurity incidents in accordance with established plans.
−Removed: Cybersecurity risks are among the core enterprise risks that are subject to oversight by the Company’s Audit Committee and ultimately, the Board of Directors (the “Board”) where that oversight and review takes place at a regular cadence.
+Added: Cybersecurity risks are among the core enterprise risks that are subject to oversight by the Company’s Audit Committee and ultimately, the Board of Directors (the “ Board ”) where that oversight and review takes place at a regular cadence through quarterly reports.
The Company’s Security & Compliance Team (“S&C Team”) has established policies, procedures, and controls to protect information assets, mitigate risks, and ensure compliance with relevant laws and regulations.
6 unchanged sentences
To facilitate the success of this program, multidisciplinary teams throughout the Company are deployed to address cybersecurity threats and to respond to cybersecurity incidents in accordance with the Company’s incident response and recovery plans.
−Removed: Through the ongoing communications from these teams, the Chief Information Security Officer monitors the prevention, detection, mitigation and remediation of cybersecurity incidents in real time, and reports such incidents to Senior Leadership and the Audit Chair when appropriate.
−Removed: In addition, the Company has established a Security Incident Response Team (“SIRT”) led by the CSO and consisting of (i) Chief Executive Officer, (ii) Chief Product Officer, (iii) Chief Financial Officer, (iv) President, Chief Operating Officer, and (v) Chief Legal Officer/ General Counsel and others.
−Removed: When any defined incident occurs, the SIRT convenes to drive a remediation plan based on its security incidence response escalation process designed to contain potential incidents, investigate the root causes and corrective action required, notify relevant stakeholders and determine reporting requirements.
+Added: Through the ongoing communications from these teams, the Chief Security Officer monitors the prevention, detection, mitigation and remediation of cybersecurity incidents in real time, and reports such incidents to Senior Leadership and the Audit Chair when appropriate.
+Added: In addition, the Company has established a Security Incident Response, Disaster Recover, and Business Continuity Team (“SIRT/DR/BCP”) led by the CSO and consisting of (i) Chief Executive Officer, (ii) Chief Product Officer, (iii) Chief Financial Officer, (iv) President, Chief Operating Officer, and (v) Chief Legal Officer/ General Counsel and others.
+Added: When any defined incident occurs, the SIRT/DR/BCP team convenes to drive a remediation plan based on its security incidence response escalation process designed to contain potential incidents, investigate the root causes and corrective action required, notify relevant stakeholders and determine reporting requirements.
The Company’s CSO is the member of the Company’s management that is principally responsible for overseeing the Company’s cybersecurity risk management program, in partnership with other business leaders across the Company.
2 unchanged sentences
The Audit Committee receives prompt and timely information regarding any cybersecurity incident that meets established reporting thresholds, as well as ongoing updates regarding such incident until it has been addressed.
−Removed: At least once each year, the Audit Committee discusses the Company’s approach to cybersecurity risk management with the Company’s CSO and Company management.
+Added: On a quarterly basis, the Audit Committee discusses the Company’s approach to cybersecurity risk management with the Company’s CSO and Company management.
This discussion may include reports on cybersecurity risks, which address a wide range of topics including, for example, recent developments, evolving standards, vulnerability assessments, third-party and independent reviews, the threat environment, technological trends and information security considerations arising with respect to the Company’s peers and third parties.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.