19 unchanged sentences
We leverage industry standard security frameworks, including from the National Institute of Standards and Technology and the International Organization for Standardization, to evaluate our security controls and manage risk.
+Added: This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use these frameworks as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
We also carry insurance that provides protection against the potential losses arising from a cybersecurity incident.
−Removed: Our Incident Response Plan coordinates the activities we take to prepare for, detect, respond to and recover from cybersecurity incidents, which include processes to triage, assess severity for, escalate, contain, investigate, and remediate the incident, as well as to comply with potentially applicable legal obligations and mitigate brand and reputational damage.
+Added: Our Incident Response Plan coordinates the activities we take to prepare for, detect, respond to and recover from cybersecurity incidents, which include processes to triage, assess severity, escalate, contain, investigate, and remediate the incident, as well as to comply with potentially applicable legal obligations and mitigate brand and reputational damage.
The incident response team assesses the severity and priority of incidents on a rolling basis.
3 unchanged sentences
Please see the risk factor “ Our business and operations could be adversely impacted in the event of a failure of information technology infrastructure.
−Removed: ” included as part of our risk factor disclosures at Item 1A of this Annual Report on Form 10-K, which disclosure is incorporated by reference herein.
+Added: ” included as part of our risk factor disclosures under Item 1A of this Annual Report on Form 10-K, which disclosure is incorporated by reference herein.
In the last three fiscal years, we have not experienced any material information security breach incidents and the expenses we have incurred from information security breach incidents were immaterial.
1 unchanged sentence
Our Board of Directors (the Board) considers risks from cybersecurity threats as part of its risk oversight function and has delegated to the Audit Committee of the Board oversight of cybersecurity and other information technology risks.
−Removed: As set forth in its charter, our Audit Committee, comprised fully of independent directors, is responsible for oversight of risk, including cybersecurity and information security risk.
+Added: As set forth in its charter, our Audit Committee, comprised fully of independent directors, is responsible for oversight of risk, including cybersecurity and information security risks.
Our Audit Committee has established a Cybersecurity Steering Committee consisting of three independent directors, Laura Black (who serves as Chair of the Cybersecurity Steering Committee), Douglas Gilstrap and Joanne Solomon, as well as our Chief Information Officer (CIO), our Chief Information Security Officer (CISO) and other members of our management representing a variety of teams and functions including legal, finance, and internal audit.
7 unchanged sentences
Our CISO, in coordination with our CIO and our Information Security team, is responsible for assessing and managing our material risks from cybersecurity threats and has primary responsibility for our overall cybersecurity risk management program and supervising both our internal cybersecurity personnel and our retained external cybersecurity consultants.
−Removed: Our CISO has more than 9 years of experience in cybersecurity and information technology risk managing, including at another large public company.
+Added: Our CISO has more than 10 years of experience in cybersecurity and information technology risk management, including at another large public company.
He also has a degree in computer science.
−Removed: Our CIO has over 15 years of information technology experience, which includes managing information security systems, developing cybersecurity strategy and implementing effective information and cybersecurity programs.
+Added: Our CIO has over 15 years of information technology experience, which includes managing information security systems, developing cybersecurity strategies and implementing effective information and cybersecurity programs.
Our CISO and CIO supervise efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, which may include briefings from internal security personnel, threat intelligence and other information obtained from governmental, public or private sources, and alerts and reports produced by security tools deployed in the IT environment, such as vulnerability assessments, penetration testing, and tabletop exercises.
2 unchanged sentences
The information set forth under the heading “Legal Proceedings” in “Note 18.
−Removed: Commitments and Contingencies” in the Notes to Consolidated Financial Statements in Item 8 of this Report is incorporated herein by reference.
+Added: Commitments and Contingencies” is under Item 8 of this Annual Report on Form 10-K.
MINE SAFETY DISCLOSURES
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.