9 unchanged sentences
Our process for identifying and assessing material risks from cybersecurity threats operates alongside our broader enterprise risk management program process, covering other Company risks.
−Removed: As part of this process our enterprise risk professionals consult with Company subject matter experts to gather information necessary to identify cybersecurity risks, and evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk.
+Added: As part of this process our enterprise risk professionals consult with subject matter experts to gather information necessary to identify cybersecurity risks, and evaluate their nature and severity, as well as identify mitigations and assess the impact of those mitigations on residual risk.
We have implemented a variety of cybersecurity processes, technologies, and controls to aid in our efforts to identify, assess and manage such risks.
1 unchanged sentence
(1) an enterprise risk management program, which includes cybersecurity risks and is periodically refreshed;
−Removed: (2) security and privacy reviews designed to identify risks from many new features, software, and vendors;
−Removed: (3) a variety of privacy, cybersecurity, and incident response trainings and simulations, including regular phishing email simulations for all employees and contractors with access to corporate email systems;
+Added: (2) security and privacy reviews designed to identify risks from new product features, software, and vendors;
+Added: (3) a variety of privacy, cybersecurity, and incident response trainings and simulations, including annual security awareness trainings and regular phishing email simulations for all employees and contractors with access to corporate email systems;
(4) tools designed to monitor our networks, systems and data for suspicious activity;
(5) the use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security controls ;
−Removed: and (6) a third-party risk management process for cybersecurity threat risks associated with our use of third-party service providers, including service providers, suppliers, and vendors.
−Removed: We leverage industry standard security frameworks, including from the National Institute of Standards and Technology and the International Organization for Standardization, to evaluate our security controls and manage risk.
−Removed: This does not imply that we meet any particular technical standards, specifications, or requirements, only that we use these frameworks as a guide to help us identify, assess, and manage cybersecurity risks relevant to our business.
−Removed: We also carry insurance that provides protection against the potential losses arising from a cybersecurity incident.
−Removed: Our Incident Response Plan coordinates the activities we take to prepare for, detect, respond to and recover from cybersecurity incidents, which include processes to triage, assess severity, escalate, contain, investigate, and remediate the incident, as well as to comply with potentially applicable legal obligations and mitigate brand and reputational damage.
−Removed: The incident response team assesses the severity and priority of incidents on a rolling basis.
−Removed: If a cybersecurity incident is determined to be a material cybersecurity incident, our incident response processes define the steps to disclose such a material cybersecurity incident.
+Added: and (6) a third-party risk management process for cybersecurity threat risks associated with our use of third-party service providers, including suppliers, and vendors.
+Added: We leverage industry standard cybersecurity frameworks, including frameworks published by the National Institute of Standards and Technology and the International Organization for Standardization, to help evaluate our security controls and manage cybersecurity risk.
+Added: We maintain ISO 27001 certification for certain in-scope products, systems or operations.
+Added: Our use of these frameworks and standards is intended to guide our cybersecurity risk management efforts and does not imply that we meet all controls under any particular framework or that our controls are fully aligned with any technical standard or that we can prevent all cybersecurity incidents or data breaches.
+Added: Additionally, we also maintain cyber liability insurance;
+Added: however, such insurance may not be sufficient to cover all losses arising from a cybersecurity incident.
+Added: Our Incident Response Plan establishes the framework for how we prepare for, detect, respond to and recover from cybersecurity incidents, including processes to triage, assess severity, escalate, contain, investigate, and remediate incidents, as well as to comply with potentially applicable legal obligations and mitigate brand and reputational damage.
+Added: The incident response team assesses the severity and priority of incidents.
+Added: If a cybersecurity incident is determined to be material, our incident response processes define the steps to disclose such a material cybersecurity incident to the relevant stakeholders.
Further, we conduct tabletop exercises to test and fortify the controls of our cybersecurity incident response program.
7 unchanged sentences
Our Audit Committee has established a Cybersecurity Steering Committee consisting of three independent directors, Laura Black (who serves as Chair of the Cybersecurity Steering Committee), Douglas Gilstrap and Joanne Solomon, as well as our Chief Information Officer (CIO), our Chief Information Security Officer (CISO) and other members of our management representing a variety of teams and functions including legal, finance, and internal audit.
−Removed: Members of our Cybersecurity Steering Committee have work experience managing cybersecurity and information security risks, an understanding of the cybersecurity threat landscape and/or knowledge of emerging privacy risks.
+Added: Members of our Cybersecurity Steering Committee have work experience managing cybersecurity and information security risks, an understanding of the cybersecurity threat landscape and knowledge of emerging privacy risks.
The purpose of the Cybersecurity Steering Committee is to oversee our compliance with reasonable and appropriate organizational, physical, administrative and technical measures designed to protect the confidentiality, integrity, availability, security and operations of our information technology systems, transactions, and data owned by us, by providing guidance and oversight of our information technology and cybersecurity program.
−Removed: The Cybersecurity Steering Committee generally meets on a quarterly basis and receives reports from the CISO and CIO of our cybersecurity and information security risk management and strategies, covering topics such as data security posture, results from third-party assessments, progress towards key initiatives, our incident response plan, and cybersecurity threat risks, incidents and developments.
+Added: The Cybersecurity Steering Committee generally meets on a quarterly basis and receives reports from the CISO and CIO of our cybersecurity and information security risk management and strategies, covering topics such as data security posture, results from third-party assessments, progress towards key cybersecurity initiatives, incident response plan, and cybersecurity threat risks, incidents and developments.
The Cybersecurity Steering Committee generally delivers reports and updates to the Audit Committee once a quarter.
The Audit Committee or, at the Audit Committee’s instruction, the Cybersecurity Steering Committee regularly briefs the full Board on these matters, and the Board receives regular updates on the status of the information security program, including but not limited to relevant cyber threats, roadmap and key initiative updates, and the identification and management of information security risks.
−Removed: Our full Board reviews cybersecurity-related opportunities as they relate to our business strategy, and cybersecurity-related matters are also factored into business continuity planning.
+Added: Our full Board considers cybersecurity-related risks, dependencies, and resilience in connection with its oversight of our business strategy, and cybersecurity-related matters are incorporated into our business continuity planning.
We have protocols by which certain cybersecurity incidents are escalated within the Company and, where appropriate, reported to the Audit Committee.
Our CISO, in coordination with our CIO and our Information Security team, is responsible for assessing and managing our material risks from cybersecurity threats and has primary responsibility for our overall cybersecurity risk management program and supervising both our internal cybersecurity personnel and our retained external cybersecurity consultants.
−Removed: Our CISO has more than 10 years of experience in cybersecurity and information technology risk management, including at another large public company.
+Added: Our CISO has more than 10 years of experience in cybersecurity and information technology risk management, including at other public companies.
He also has a degree in computer science.
8 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.