16 unchanged sentences
In addition to our in-house cybersecurity capabilities, we also engage assessors, consultants and other third parties to assist with various cybersecurity matters.
−Removed: For example, Verizon validates enterprise cybersecurity maturity every two years through a third-party maturity assessment.
+Added: For example, Verizon periodically validates enterprise cybersecurity maturity through a third-party maturity assessment.
This assessment measures Verizon’s ability to identify, prevent, detect, respond to, and recover from threats to systems, assets and data.
10 unchanged sentences
Verizon effectuates cybersecurity management by providing for close cooperation among the CISO’s team and other teams within the company, as well as by integrating cybersecurity risk into Verizon’s overall enterprise risk management structures and processes.
−Removed: Each of our business units and certain functional groups have a Business Information Security Officer, who is an integral member of that unit or group, but reports to the CISO.
+Added: Our business units and certain functional groups have a Business Information Security Officer, who is an integral member of that unit or group, but reports to the CISO.
This structure provides the CISO with line of sight across the enterprise.
−Removed: The CISO and members of her leadership team also meet regularly with business unit senior leaders, including the CEO, the Chief Financial Officer (CFO) and the Chief Human Resources Officer, to discuss business priorities, emerging threats and trends, and the performance of the cybersecurity program.
−Removed: The Verizon Executive Security Council (VESC) oversees and evaluates the work of the CISO and their team.
−Removed: The VESC is jointly chaired by the head of Verizon Global Services and the President of Global Networks and Technology and includes Verizon’s Chief Compliance Officer, Chief Legal Officer, Senior Vice President of Internal Audit and senior executives in business and technology functions.
+Added: The CISO and members of her leadership team also meet regularly with business unit senior leaders, including the CEO and the Chief Financial Officer (CFO), to discuss business priorities, emerging threats and trends, and the performance of the cybersecurity program.
+Added: The Verizon Executive Security Council (VESC) is the governing body for Verizon's cybersecurity program.
+Added: The VESC is chaired by the CISO.
+Added: The principal members are the key business, technology, network, legal, finance, audit, and compliance leaders from the business units and corporate functions.
The VESC provides oversight of all aspects of Verizon’s cybersecurity program and, at regular intervals throughout the year, evaluates key cybersecurity metrics as well as planned and ongoing initiatives to reduce cybersecurity risks.
−Removed: Verizon’s Management Audit Committee (VMAC), which includes our CFO, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy.
−Removed: The VMAC receives quarterly updates from the CISO on Verizon’s cybersecurity program.
+Added: Verizon’s Risk Committee, which includes our CFO, Senior Vice President of Internal Audit and other senior executives, is responsible for overseeing components of our overall risk management strategy.
+Added: The Risk Committee receives periodic updates from the CISO on Verizon’s cybersecurity program.
Verizon also operates a robust internal audit program.
2 unchanged sentences
Board Oversight of Cybersecurity Risk
−Removed: The Audit Committee of the Board of Directors (Board) has primary responsibility for overseeing Verizon’s risk management and compliance programs relating to cybersecurity and data protection and privacy.
+Added: The Audit Committee of the Board of Directors (Board) has primary responsibility for overseeing Verizon’s risk management and compliance programs relating to cybersecurity, data security and data privacy.
As part of the Board’s oversight of risks from cybersecurity threats, the CISO leads an annual review and discussion with the full Board dedicated to Verizon’s cybersecurity risks, threats and protections.
10 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.