26 unchanged sentences
We have implemented a governance framework related to cybersecurity that includes operational risk-mitigation practices and Board-level cybersecurity risk oversight.
−Removed: Our management team is charged with managing cybersecurity risk and identifying material cybersecurity risk exposures to our company and carries out this function primarily through our Information Security organization, which is led by our Chief Information Security Officer who has a master’s degree in computer science, over a decade of information security leadership, and thirty years of combined IT leadership experience.
+Added: Our management team is charged with managing cybersecurity risk and identifying material cybersecurity risk exposures to our company and carries out this function primarily through our Information Security organization, which is led by our Chief Information Security Officer who has a master’s degree in computer science, over a decade of information security leadership, and thirty years of combined information technology (“IT”) leadership experience.
Additionally, our Cyber Incident Response Plan discussed above calls for the establishment of a management Impact Assessment Committee, which consists of key leadership representatives from the organization and is convened on an ad hoc basis to assess the detailed business impact of a cybersecurity incident.
3 unchanged sentences
Our Board of Directors is responsible for overseeing the cybersecurity risk management process and exercises this risk oversight through both our full Board of Directors and its Audit Committee.
−Removed: Our Board of Directors has delegated to our Audit Committee the responsibility to oversee risks related to cybersecurity threats, and our Audit Committee Charter requires our Audit Committee to review and discuss with management the Company’s policies with respect to risk assessment and enterprise risk management and to review the risk exposure of the Company related to the Committee’s areas of responsibility, including with respect to cybersecurity.
+Added: Our Board of Directors has delegated to our Audit Committee the responsibility to oversee risks related to cybersecurity threats, and our Audit Committee Charter requires our Audit Committee to review and discuss with management the Company’s policies with respect to risk assessment and ERM and to review the risk exposure of the Company related to the Committee’s areas of responsibility, including with respect to cybersecurity.
In carrying out this role, our Audit Committee meets with our Chief Information Security Officer regularly and receives at least quarterly reports on cybersecurity matters.
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.