4 unchanged sentences
The program is built on the following pillars:
−Removed: • NIST Cybersecurity Framework.
−Removed: Our program is aligned to the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework, which outlines the core components and responsibilities necessary to sustain a healthy and well-balanced cybersecurity program.
−Removed: • Risk identification.
−Removed: We continually assess the cybersecurity threat and vulnerability landscape using various commercial, government and publicly available information sources.
−Removed: • Risk detection.
−Removed: We use both manual and automated detection methods on a scheduled and ad-hoc basis to identify vulnerabilities within, and threats to, our operations and network infrastructure.
−Removed: • Risk evaluation.
−Removed: Once a cybersecurity vulnerability is detected, we assign a threat severity classification based on the risk profile associated with the vulnerability.
−Removed: • Remediation.
−Removed: Verizon’s information security team reports all cybersecurity vulnerabilities and their associated threat classification to the appropriate business team for remediation.
+Added: • NIST Cybersecurity Framework - Our program is aligned to the National Institute of Standards and Technology’s (NIST) Cybersecurity Framework, which outlines the core components and responsibilities necessary to sustain a healthy and well-balanced cybersecurity program.
+Added: • Risk identification - We continually assess the cybersecurity threat and vulnerability landscape using various commercial, government and publicly available information sources.
+Added: • Risk detection - We use both manual and automated detection methods on a scheduled and ad-hoc basis to identify vulnerabilities within, and threats to, our operations and network infrastructure.
+Added: • Risk evaluation - Once a cybersecurity vulnerability is detected, we assign a threat severity classification based on the risk profile associated with the vulnerability.
+Added: • Remediation - Verizon’s information security team reports all cybersecurity vulnerabilities and their associated threat classification to the appropriate business team for remediation.
Deadlines for remediation are set based on the severity of the threat and closely tracked in a central system of record.
In the instances when a remediation deadline cannot be met, the information security team and the business team work together to deploy appropriate mitigating or compensating controls until the remediation work is complete.
−Removed: • Metrics and analysis.
−Removed: We track the performance of our cybersecurity program by collecting, retaining and analyzing a broad range of data related to our threat identification, detection and response activity.
+Added: • Metrics and analysis - We track the performance of our cybersecurity program by collecting, retaining and analyzing a broad range of data related to our threat identification, detection and response activity.
We use this data to assess threat trends, for strategic planning purposes and to enhance management accountability for cybersecurity.
−Removed: Verizon has a comprehensive enterprise cybersecurity incident response plan, which is activated in the event of a cybersecurity incident.
−Removed: The plan is a detailed playbook that specifies how Verizon classifies, responds to, and recovers from cybersecurity incidents and includes notification procedures that vary depending on the significance of the incident.
−Removed: When warranted by the severity of the incident, our Chief Executive Officer and other senior executives are part of the notification chain.
−Removed: Verizon validates enterprise cybersecurity maturity every two years through a third-party maturity assessment.
+Added: Our processes for assessing, identifying, and managing cybersecurity risks include tabletop exercises to test and reinforce our incident response controls, control gap analyses, penetration tests, data recovery testing, internal and external security assessments, and threat intelligence monitoring.
+Added: We also conduct annual cybersecurity and data privacy training, which is mandatory for all our full- and part-time employees.
+Added: In addition to our in-house cybersecurity capabilities, we also engage assessors, consultants and other third parties to assist with various cybersecurity matters.
+Added: For example, Verizon validates enterprise cybersecurity maturity every two years through a third-party maturity assessment.
This assessment measures Verizon’s ability to identify, prevent, detect, respond to, and recover from threats to systems, assets and data.
1 unchanged sentence
In addition to this baseline, certain subsets of our technology environment are subject to incremental cybersecurity certification and periodic third party validation under applicable regulatory or contractual requirements.
+Added: Verizon has a comprehensive enterprise cybersecurity incident response plan, which is activated in the event of a cybersecurity incident.
+Added: The plan is a detailed playbook that specifies how Verizon classifies, responds to, and recovers from cybersecurity incidents and includes notification procedures that vary depending on the significance of the incident.
+Added: When warranted by the severity of the incident, our Chief Executive Officer (CEO) and other senior executives are part of the notification chain.
Integrated Cybersecurity Risk Management
Verizon’s Senior Vice President and Chief Information Security Officer (CISO) has responsibility for the management of cybersecurity risks at Verizon.
−Removed: The CISO and their team are responsible for Verizon’s information security strategy, policy, standards, architecture and processes.
−Removed: The CISO brings nearly two decades of cybersecurity experience to their work at Verizon.
−Removed: Prior to joining Verizon, they held executive-level cybersecurity roles at other large public companies, where they were responsible for cybersecurity strategy and operations, including incident response, threat intelligence, security services, architecture, commercial operational technology security, and regulatory and compliance matters.
+Added: The CISO and her team are responsible for Verizon’s information security strategy, policy, standards, architecture and processes.
+Added: The CISO brings nearly two decades of cybersecurity experience to her work at Verizon.
+Added: Prior to joining Verizon, she held executive-level cybersecurity roles at other large public companies, where she was responsible for cybersecurity strategy and operations, including incident response, threat intelligence, security services, architecture, commercial operational technology security, and regulatory and compliance matters.
Verizon effectuates cybersecurity management by providing for close cooperation among the CISO’s team and other teams within the company, as well as by integrating cybersecurity risk into Verizon’s overall enterprise risk management structures and processes.
1 unchanged sentence
This structure provides the CISO with line of sight across the enterprise.
−Removed: The CISO and members of their leadership team also meet regularly with business unit senior leaders, including the CEO, the Chief Financial Officer and the Chief Human Resources Officer, to discuss business priorities, emerging threats and trends, and the performance of the cybersecurity program.
+Added: The CISO and members of her leadership team also meet regularly with business unit senior leaders, including the CEO, the Chief Financial Officer (CFO) and the Chief Human Resources Officer, to discuss business priorities, emerging threats and trends, and the performance of the cybersecurity program.
The Verizon Executive Security Council (VESC) oversees and evaluates the work of the CISO and their team.
−Removed: The VESC is jointly chaired by the presidents of Verizon Global Services and Global Networks and Technology and includes Verizon’s Chief Compliance Officer, Chief Legal Officer, Senior Vice President of Internal Audit and senior executives in business and technology functions.
+Added: The VESC is jointly chaired by the head of Verizon Global Services and the President of Global Networks and Technology and includes Verizon’s Chief Compliance Officer, Chief Legal Officer, Senior Vice President of Internal Audit and senior executives in business and technology functions.
The VESC provides oversight of all aspects of Verizon’s cybersecurity program and, at regular intervals throughout the year, evaluates key cybersecurity metrics as well as planned and ongoing initiatives to reduce cybersecurity risks.
−Removed: Verizon’s Management Audit Committee (VMAC), which includes our Chief Financial Officer, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy.
+Added: Verizon’s Management Audit Committee (VMAC), which includes our CFO, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy.
The VMAC receives quarterly updates from the CISO on Verizon’s cybersecurity program.
7 unchanged sentences
The Audit Committee also receives a report from senior management on Verizon’s cybersecurity posture and related matters at each of its other meetings during the year at which the CISO is not present.
−Removed: Supplier Risk Management
+Added: Third Party Risk Management
We have implemented processes to identify and manage risks from cybersecurity threats associated with our use of third-party service providers.
−Removed: The Verizon Supplier Risk Management Program establishes governance, processes and tools for managing various supplier-related risks, including information security.
+Added: The Verizon Third Party Risk Management Program establishes governance, processes and tools for managing various supplier-related risks, including information security.
As a condition of working with Verizon, suppliers who access sensitive business or customer information are expected to meet certain information security requirements.
Risks from Cybersecurity Threats
−Removed: We are subject to increasing and evolving cybersecurity threats as cyber attacks against companies, including Verizon, have increased in frequency, scope and potential harm in recent years.
−Removed: While, to date, we have not been subject to cyber attacks that, individually or in the aggregate, have been material to Verizon's operations or financial condition, there can be no guarantee that we will not experience such an incident in the future.
−Removed: For more information on the risks from cybersecurity threats that we face, refer to “Risk Factors — Operational Risks — Cyber attacks impacting our networks or systems could have an adverse effect on our business” in Part I, Item 1A of this Annual Report on Form 10-K.
+Added: We are subject to increasing and evolving cybersecurity threats as cyberattacks against companies, including Verizon, have increased in frequency, scope and potential harm in recent years.
+Added: While none of the cyberattacks to which we have been subject to date have been material to Verizon's operations or financial condition, there can be no guarantee that we will not experience a material cyberattack in the future.
+Added: For more information on the risks from cybersecurity threats that we face, refer to “Risk Factors — Operational Risks — Cyberattacks impacting our networks or systems could have an adverse effect on our business” in Part I, Item 1A of this Annual Report on Form 10-K.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.