3 unchanged sentences
Our business is substantially dependent upon our computer systems, devices and networks to collect, process and store the data necessary to conduct most aspects of our business.
−Removed: We have developed and maintain a cybersecurity program, which includes people, processes, and technology aimed at defending our computer systems, devices and networks against increasingly sophisticated threats.
+Added: We have developed and maintained a cybersecurity program, which includes people, processes, and technology aimed at defending our computer systems, devices and networks against increasingly sophisticated threats.
Cybersecurity risk management is an integral part of our enterprise risk management program.
1 unchanged sentence
The NIST framework facilitates coordination across different departments of the Company and includes steps for assessing the severity of a cybersecurity threat, identifying the source of a threat, including whether the threat is associated with a third-party service provider, implementing countermeasures and mitigation strategies, and informing management and the Board of Directors of material cybersecurity threats, incidents, and impact.
−Removed: Our cybersecurity team is under the direction of the Chief Operations Officer and VP of Technology and Information Security, who are responsible for assessing, deploying, and managing the cybersecurity risk management program.
+Added: Our cybersecurity team is under the direction of the Chief Operations Officer ("COO") and VP of Technology and Information Security ("VPTIS"), who are responsible for assessing, deploying, and managing the cybersecurity risk management program.
Recognizing the complexity and evolving nature of cybersecurity threats, the cybersecurity team engages with a range of independent third-party experts , including cybersecurity assessors and consultants in evaluating and testing our risk management systems.
15 unchanged sentences
• Patch management – we use a network vulnerability scanning tool that continually scans, and reports identified vulnerabilities in servers and workstations in certain networks.
−Removed: Vulnerability scanner reports are used to drive patching and remediation efforts and are also used as a tool to evaluate the effectiveness of efforts to seek to ensure patches are applied timely.
+Added: Vulnerability scanner reports are used to drive patching
+Added: and remediation efforts and are also used as a tool to evaluate the effectiveness of efforts to seek to ensure patches are applied timely.
Application and infrastructure subject matter experts subscribe to various third-party vendor security notifications to receive proactive notifications on, among other things, bugs, security flaws and mitigations, related to operational and information systems.
3 unchanged sentences
The Board of Directors is responsible for ensuring that management has processes in place that are designed to identify and evaluate cybersecurity risks to which the Company is exposed and implement programs to manage cybersecurity risks and mitigate cybersecurity incidents.
−Removed: Management under the Chief Operations Officer and VP of Technology and Information Security are responsible for identifying, considering, and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential risk exposures are monitored, implementing appropriate mitigation measures and maintaining cybersecurity programs.
−Removed: The Chief Operations Officer and VP of Technology and Information Security and cybersecurity team members are experienced information security professionals, many of whom hold professional certifications and many years of experience in the field.
−Removed: The Chief Operations Officer and VP of Technology and Information Security receive periodic reports from the cybersecurity team and monitors the prevention, detection, mitigation, and remediation of cybersecurity incidents.
+Added: The cybersecurity team, under the direction of the COO and VPTIS, are responsible for identifying, considering, and assessing material cybersecurity risks on an ongoing basis, establishing processes to ensure that such potential risk exposures are monitored, implementing appropriate mitigation measures and maintaining cybersecurity programs.
+Added: The COO, VPTIS and cybersecurity team members are experienced information security professionals, many of whom hold professional certifications and many years of experience in the field.
+Added: The COO and VPTIS receive periodic reports from the cybersecurity team and monitor the prevention, detection, mitigation, and remediation of cybersecurity incidents.
Appropriate procedures for communication to the Executive Team are also built into the incident response plan.
−Removed: The Chief Operations Officer and VP of Technology and Information Security provide regular updates to the Executive Team and the full Board of Directors on the Company’s cybersecurity risk management program, material cybersecurity risks, and mitigation strategies.
+Added: The COO and VPTIS provide regular updates to the Executive Team and the full Board of Directors on the Company’s cybersecurity risk management program, material cybersecurity risks, and mitigation strategies.
Management provides the Executive Team with cybersecurity reports that cover, among other topics, third-party assessments of the Company’s cybersecurity risk management program, developments in cybersecurity, and updates to the Company’s cybersecurity risk management program and mitigation strategies.
7 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.