18 unchanged sentences
Our CISO leads Walmart's Information Security organization and has responsibility for overseeing our Company's cybersecurity program.
−Removed: To operationalize our program, we deploy multidisciplinary teams, including cybersecurity personnel and professionals, to address cybersecurity threats and respond to cybersecurity incidents, including for those non-wholly owned subsidiaries whose systems have not been fully integrated into Walmart's networks.
+Added: To operationalize our program, we deploy multidisciplinary teams, including cybersecurity personnel and professionals, to address cybersecurity threats and respond to cybersecurity incidents, including for those recently acquired and non-wholly owned subsidiaries whose systems have not been fully integrated into Walmart's networks.
Through ongoing engagement with these teams and certain third-party service providers, our CISO monitors the prevention, detection, mitigation and remediation of cybersecurity threats and incidents and reports cybersecurity incidents that reach established thresholds to senior management and the Audit Committee, which are also analyzed for external reporting requirements.
−Removed: Our CISO has been a Walmart associate for over 30 years, has served in various roles in information technology and information security at Walmart for almost 20 years, and has received industry-recognized information security certifications.
+Added: Our CISO has been a Walmart associate for over 30 years, has served in various roles in information technology and information security at Walmart for more than 20 years, and has received industry-recognized information security certifications.
Our CTO, to whom the CISO reports, has served as Walmart's CTO since 2019 and prior to that had experience managing technology and other risks at several other large public companies.
Risk Management and Strategy
−Removed: Our cybersecurity program is informed by various industry frameworks including the National Institute of Standards and Technology Cybersecurity Framework for Improving Critical Infrastructure Cybersecurity (NIST-CSF Version 1.1), which are reflected in our related policies, standards, processes and practices.
−Removed: We may implement changes to our cybersecurity program when deemed necessary based on updates to industry standards among other things.
−Removed: We have multiple layers of security designed to detect and block cybersecurity events, as well as dedicated teams of cybersecurity personnel and professionals, which assist our CISO in helping to assess, identify, monitor, detect and manage cybersecurity risks, threats, vulnerabilities and incidents.
−Removed: We collaborate with public and private entities and industry groups and engage third-party service providers to expand the capabilities and capacity of our cybersecurity program when deemed necessary.
+Added: Our cybersecurity program is informed by various industry frameworks including the National Institute of Standards and Technology Cybersecurity Framework (NIST-CSF), which are reflected in our related policies, standards, processes and practices.
+Added: We may implement changes to our cybersecurity program when deemed appropriate based on updates to laws or industry standards among other things.
+Added: We have multiple layers of security designed to detect and prevent cybersecurity events, as well as dedicated teams of cybersecurity personnel and professionals, which assist our CISO in helping to assess, identify, monitor, detect and manage cybersecurity risks, threats, vulnerabilities and incidents.
+Added: We collaborate with public and private entities and industry groups and engage third-party service providers to expand the capabilities and capacity of our cybersecurity program when deemed appropriate.
Certain key components of our cybersecurity program include the following:
15 unchanged sentences
These efforts include tabletop exercises, threat modeling, vulnerability testing and other exercises focused on evaluating the effectiveness of our cybersecurity measures and planning.
−Removed: We regularly engage third parties to assist with our assessments and testing.
+Added: We regularly engage assessors, consultants, auditors or other third parties to assist with our assessments and testing.
Where appropriate we adjust our cybersecurity policies, standards, processes and practices accordingly based on internal and external assessment and testing results.
5 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.