Item 1B. Unresolved Staff Comments
6K characters. Original on sec.gov · Markdown
Item 1B. Unresolved Staff Comments
There are no unresolved written comments that were received from the SEC staff 180 days or more before the end of our fiscal year relating to periodic or current reports under the Exchange Act.
| AIG | 2023 Form 10-K | 37 |
ITEM 1C | Cybersecurity
ITEM 1C | Cybersecurity
CYBERSECURITY RISK MANAGEMENT
AIG maintains a documented Information Security Program (the Program) that includes risk assessments regularly conducted by us and third-party experts to evaluate potential security threats that may have a negative impact on the organization, detect potential vulnerabilities and mitigate any identified security risks. The Program is informed by industry standards and frameworks and is designed to protect the confidentiality, integrity, and availability of AIG’s information assets and systems that store, process or transmit information.
The AIG Chief Information Security Officer (CISO) provides oversight and direction for the Program, including adjustments in response to changes in technology, internal or external threats, business processes, and regulatory or statutory requirements and communicates the information security risk posture of AIG to senior management and the AIG Board of Directors.
The Program includes the following key elements:
-
Network, Systems and Data Security – The Company deploys technical and organizational safeguards that are designed to protect the Company’s networks, systems, and data from cybersecurity threats, including firewalls, intrusion prevention and detection systems, anti-malware functionality, and access controls.
-
Threat and Vulnerability Management – The Company maintains a threat and vulnerability management program that leverages continuous threat intelligence to seek to proactively identify, assess, and mitigate evolving cybersecurity risks. This program incorporates vulnerability scanning, remediation management, bug bounty, penetration testing, and threat response capabilities, all designed to safeguard our information assets and ensure business continuity.
-
Cybersecurity Incident Monitoring and Response – The Company has established and maintains incident response plans that address the Company’s response to a cybersecurity incident, utilizing a cross-functional approach.
-
Third Party Assessment and Oversight – The Company maintains a third-party risk management program designed to identify and manage cybersecurity risks from third-party service providers, including initial due diligence and assessment of the service provider’s control environment as well as periodic re-assessments.
-
Security Training and Awareness – The Company provides ongoing education and training to employees regarding information security threats, and their role and responsibility in detecting and responding to such threats.
In addition to the above, where appropriate, AIG employs third-party experts to evaluate our cybersecurity risk management program. The Company conducts annual external penetration tests to simulate real-world attacks against the Company’s networks and applications which supplement our continuous internal application security assessments. These independent evaluations help uncover potential security vulnerabilities for remediation by our cybersecurity team. We also operate a bug bounty program through a crowdsourced security platform to incentivize responsible disclosure of software defects by global security researchers.
The Program is evaluated on an ongoing basis both internally and through the use of third-party audit firms to address and protect against the evolving cyber threat landscape and seeks to align to industry standards such as the National Institute of Standards and Technology Cybersecurity Framework, as well as applicable legal and regulatory guidance and mandates related to all AIG stakeholders, including investors, customers, and employees. Control adequacy and design are reviewed at least annually, and independent audits and penetration tests assist in identifying areas for continued focus, improvement and/or inclusion, and are designed to provide assurance that controls are appropriately designed and operating effectively. Additionally, the Company's Internal Audit group performs independent testing of the Company’s control environment, including key components of the Program.
Board Oversight and Governance
AIG's Board of Directors (the Board) oversees the Program and management of risks from cybersecurity threats and reviews and monitors AIG's business and technology strategy, including the policies, processes and practices that the Company’s management implements to address risks from cybersecurity threats. The Board believes that all directors are responsible for oversight of these matters given the increasing importance of cybersecurity to AIG’s risk profile, as well as the significant role the Company’s technology strategy plays in its strategic priorities. The Chief Information Officer (CIO), CISO and Chief Risk Officer provide updates to the Board as appropriate.
Global Committees
Group Risk Committee (GRC): The GRC is a committee comprised of senior management and is responsible for assessing significant risk issues on a global basis to protect AIG’s financial strength, optimize AIG’s intrinsic value, and protect AIG’s reputation. The risks considered by the GRC include those relating to cybersecurity.
| 38 | AIG | 2023 Form 10-K |
Previous: Item 1A. Risk Factors · Next: Item 1C. Cybersecurity