21 unchanged sentences
Our board of directors and audit and risk committee’s principal role is one of oversight, recognizing that management is responsible for the design, implementation, and maintenance of an effective program for protecting against and mitigating data privacy and cybersecurity risks.
−Removed: The audit and risk committee assists the board of directors in enhancing its understanding of data privacy and cybersecurity issues by overseeing our data privacy and information security programs, strategy, policies, standards, architecture, processes, and significant risks, as well as overseeing responses to security and data incidents, as appropriate.
−Removed: The full board of directors undergoes annual information security and privacy training by our Chief Information Security Officer (“CISO”) and our Chief Privacy Officer (“CPO”), which covers, among other matters, our privacy and cybersecurity programs and risks.
−Removed: Our audit and risk committee receives updates, at least quarterly, from our CISO and CPO on significant data privacy and security risks, including any significant incidents, relevant industry developments, threat vectors and significant risks identified in periodic penetration tests or vulnerability scans.
+Added: The audit and risk committee assists the board of directors in enhancing its understanding of data privacy and cybersecurity issues by overseeing our data privacy and information security programs, strategy, policies, processes, and material risks, as well as overseeing responses to security and data incidents, as appropriate.
+Added: The full board of directors receives an annual information security update by our Chief Information Security Officer (“CISO”) and an annual privacy update, which covers, among other matters, our privacy and cybersecurity programs and risks.
+Added: Our audit and risk committee receives updates, at least quarterly, on significant data privacy and security risks, including any significant incidents, relevant industry developments, threat vectors and significant risks identified in periodic penetration tests or vulnerability scans.
The updates also include significant legal and legislative developments concerning data privacy and security, our approach to complying with applicable law, and significant engagement with regulators concerning data privacy and cybersecurity.
−Removed: Our audit committee provides regular updates to the board of directors on such reports.
+Added: Our audit and risk committee provides regular updates to the board of directors on such reports.
Our CISO oversees our cybersecurity policies and processes, including those described in “Risk Management and Strategy” above.
−Removed: Our foundational engineering, data security governance, infrastructure security, product security and security operations teams report directly to our CISO and provide regular updates on significant or potentially significant threats and incidents.
+Added: Our data security governance, infrastructure security, product security, applied security engineering and security operations teams report directly to our CISO and provide regular updates on significant or potentially significant threats and incidents.
Additionally, we have an incident response team and an incident response plan that outlines the roles and responsibilities of key personnel, including representatives from information security, compliance, and counsel, that are involved in responding to, remediating and escalating such incidents to the CISO, as appropriate.
−Removed: Our CISO reports directly to our Chief Financial Officer and Chief Operating Officer and indirectly to our audit and risk committee.
+Added: Our CISO reports directly to our Technology + Engineering Lead and indirectly to our audit and risk committee.
Our CISO provides updates on significant or potentially significant threats and incidents to our Block Head and leadership team, in addition to the audit and risk committee and our board of directors as appropriate and in accordance with the processes detailed in the prior paragraph.
−Removed: Our CISO and Deputy CISO are primarily responsible for assessing and managing our material risks from cybersecurity threats.
−Removed: Our CISO has served in various roles building and securing enterprise platforms across retail, corporate and investment banking financial services as well as consumer experiences and data at multiple Fortune 500 companies for over 25 years.
−Removed: Our Deputy CISO has over 20 years of experience in information security, including serving as head of cybersecurity and privacy response at a global public company and information security leadership positions with the United States government.
−Removed: Our Deputy CISO holds undergraduate and graduate degrees in computer information systems and computer science with an information security focus and possesses various certifications, including the Information Systems Security Professional (NSTISSI No.
+Added: Our CISO is primarily responsible for assessing and managing our material risks from cybersecurity threats.
+Added: Our CISO has over 20 years of experience in information security, including serving as head of cybersecurity and privacy response at a global public company and information security leadership positions with the United States government.
+Added: Our CISO holds undergraduate and graduate degrees in computer information systems and computer science with an information security focus and possesses various certifications, including the Information Systems Security Professional (NSTISSI No.
4011) and Information Systems Security Officer (CNSSI No.
1 unchanged sentence
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.