UNRESOLVED STAFF COMMENTS
−Removed: Item 1B is not applicable to smaller reporting companies.
−Removed: CYBERSECURITY
−Removed: Cybersecurity
−Removed: Risk Management and Strategy
−Removed: cybersecurity risk management program, processes and strategy described in this section are limited to the personal and business information
−Removed: belonging to or maintained by the Company (collectively, “Confidential Information”), our own third-party critical systems
−Removed: and services supporting or used by the Company (collectively, “Critical Systems”), and service providers.
−Removed: The Company’s
−Removed: subsidiaries lease to our tenants the properties we own, but we do not have actual or contractual access to the systems or information
−Removed: maintained or used by our tenants.
−Removed: Our tenants are directly or indirectly (through their own service providers) responsible for maintaining
−Removed: programs and processes to protect their systems and information from various risks from cybersecurity threats.
−Removed: will develop and implement a cybersecurity risk management program intended to protect the confidentiality, integrity, and availability
−Removed: of our Confidential Information and Critical Systems.
−Removed: Our cybersecurity risk management program will be integrated into our overall enterprise
−Removed: risk management program and includes a cybersecurity incident response plan.
−Removed: cybersecurity risk management program shall include:
−Removed: assessments designed to help identify material cybersecurity risks to our Confidential Information,
−Removed: Critical Systems and the broader enterprise IT environment;
−Removed: security team principally responsible for managing (1) our cybersecurity risk assessment
−Removed: processes, (2) our security controls, and (3) our response to cybersecurity incidents;
−Removed: ● cybersecurity
−Removed: awareness and spear-phishing resistance training of our employees, and senior management;
−Removed: cybersecurity incident response plan that includes procedures for responding to cybersecurity
−Removed: vendor management policy for service providers.
−Removed: have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents, that have materially
−Removed: affected or are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial
−Removed: We face risks from cybersecurity threats that, if realized, could have a material adverse effect on us including an adverse
−Removed: effect on our business, financial condition and results of operations.
+Added: This Item 1B is not applicable to smaller reporting companies.
CYBERSECURITY
−Removed: executive management team, along with our managed information technology service provider, is responsible for assessing and managing
−Removed: risks from cybersecurity threats to the Company, including our Confidential Information and Critical Systems.
−Removed: The team has primary responsibility
−Removed: for our overall cybersecurity risk management program.
+Added: Cybersecurity Risk Management and Strategy
+Added: The cybersecurity risk management program, processes
+Added: and strategy described in this section are limited to the personal and business information belonging to or maintained by the Company
+Added: (collectively, “Confidential Information”), our own third-party critical systems and services supporting or used by the Company
+Added: (collectively, “Critical Systems”), and service providers.
+Added: The Company’s subsidiaries lease to our tenants the properties
+Added: we own, but we do not have actual or contractual access to the systems or information maintained or used by our tenants.
+Added: are directly or indirectly (through their own service providers) responsible for maintaining programs and processes to protect their
+Added: systems and information from various risks from cybersecurity threats.
+Added: We will develop and implement a cybersecurity
+Added: risk management program intended to protect the confidentiality, integrity, and availability of our Confidential Information and Critical
+Added: Our cybersecurity risk management program will be integrated into our overall enterprise risk management program and includes
+Added: a cybersecurity incident response plan.
+Added: Our cybersecurity risk management program shall include:
+Added: assessments designed to help identify material cybersecurity risks to our Confidential Information, Critical Systems and the broader
+Added: enterprise IT environment;
+Added: security team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and
+Added: (3) our response to cybersecurity incidents;
+Added: cybersecurity awareness
+Added: and spear-phishing resistance training of our employees, and senior management;
+Added: cybersecurity incident response plan that includes procedures for responding to cybersecurity incidents;
+Added: a vendor management policy
+Added: for service providers.
+Added: We have not identified risks from known cybersecurity
+Added: threats, including as a result of any prior cybersecurity incidents, that have materially affected or are reasonably likely to materially
+Added: affect us, including our operations, business strategy, results of operations, or financial condition.
+Added: We face risks from cybersecurity
+Added: threats that, if realized, could have a material adverse effect on us including an adverse effect on our business, financial condition
+Added: and results of operations.
+Added: Cybersecurity Governance
+Added: Our executive management team , along with our
+Added: managed information technology service provider, is responsible for assessing and managing risks from cybersecurity threats to the Company,
+Added: including our Confidential Information and Critical Systems.
+Added: The team has primary responsibility for our overall cybersecurity risk management
Our management team works closely with our information technology service provider.
−Removed: management team meets with our information technology service provider periodically to discuss then-current cybersecurity issues, which
−Removed: may include efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, including threat
−Removed: intelligence and other information obtained from governmental, public or private sources, and external service providers engaged by us;
−Removed: and alerts and reports produced by security tools deployed in the information technology environment including a spear-phishing report.
−Removed: Board considers cybersecurity risk as part of its risk oversight function and oversight of cybersecurity and other information technology
−Removed: Board oversees management’s implementation of our cybersecurity risk management program.
−Removed: Our executive management team is responsible
−Removed: for updating the Board, as necessary, regarding significant cybersecurity incidents.
−Removed: Board shall also receive period reports from management on our cybersecurity risks and cybersecurity risk management program.
+Added: Our management team meets with our information technology service
+Added: provider periodically to discuss then-current cybersecurity issues, which may include efforts to prevent, detect, mitigate, and remediate
+Added: cybersecurity risks and incidents through various means, including threat intelligence and other information obtained from governmental,
+Added: public or private sources, and external service providers engaged by us;
+Added: and alerts and reports produced by security tools deployed in
+Added: the information technology environment including a spear-phishing report.
+Added: Our Board considers cybersecurity risk as part
+Added: of its risk oversight function and oversight of cybersecurity and other information technology risks.
+Added: Our Board oversees management’s implementation
+Added: of our cybersecurity risk management program.
+Added: Our executive management team is responsible for updating the Board, as necessary, regarding
+Added: significant cybersecurity incidents.
+Added: Our Board shall also receive period reports from
+Added: management on our cybersecurity risks and cybersecurity risk management program.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.