16 unchanged sentences
The Company utilizes various technical and qualitative processes to assist in identifying, assessing and managing cybersecurity risks.
−Removed: The Company's processes include periodic discussions and risk reviews with management and, depending on facts and circumstances, may include internal audits, third-party assessments, post-remediation reviews, engagements with independent third-party service providers and key governmental agencies, regular employee training, an incident response plan and backup and recovery plans.
+Added: The Company's processes include periodic discussions and risk reviews with management.
+Added: These processes also include, depending on facts and circumstances, internal audits, third-party assessments, post-remediation reviews, engagements with independent third-party service providers and key governmental agencies, regular employee training, an incident response plan and backup and recovery plans.
Our periodic engagements with independent third-party service providers are designed to provide qualitative and technical cybersecurity assessments.
2 unchanged sentences
Certain of the Company's subsidiaries have separate cybersecurity teams that, along with the corporate-level cybersecurity team, play a role in the Company's efforts to monitor, identify, assess and manage cybersecurity risks.
−Removed: We interact with the information technology networks and systems of third parties for many aspects of our business.
+Added: The Company interacts with the information technology networks and systems of third parties for many aspects of our business.
We consider and evaluate cybersecurity risks associated with the use of independent third-party service providers.
−Removed: To help UPS understand and mitigate potential cybersecurity risks, we generally utilize measures such as vendor risk assessments, periodic technical assessments of third-party vendors' controls and contracts governing the use of and access to our data and compliance with our security requirements.
+Added: To help UPS understand and mitigate potential cybersecurity risks related to third parties, we generally utilize measures such as vendor risk assessments, periodic technical assessments of third-party vendors' controls and contracts governing the use of and access to our data and compliance with our security requirements.
We maintain an Incident Response Plan that includes processes and procedures for reviewing and responding to cybersecurity incidents.
3 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.