3 unchanged sentences
The company’s cybersecurity program is designed to protect its information assets and operations from external and internal cyber threats by identifying and appropriately managing and mitigating risks while ensuring business resiliency.
−Removed: This program is integrated within the company’s Enterprise Risk Management (ERM) process, which is the company’s systematic approach to identifying, managing and assessing major risks and safeguards,
−Removed: including cybersecurity risks.
+Added: This program is integrated within the company’s Enterprise Risk Management (ERM) process, which is the company’s systematic approach to identifying, managing and assessing major risks and safeguards, including cybersecurity risks.
Chevron uses a risk-based information security process aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework to identify, prioritize and mitigate cyber risks.
8 unchanged sentences
As third-party risks increase, the company’s approach to third-party supplier risk management and qualification continues to evolve, including the ongoing expansion of its current supplier risk management program beyond IT vendors to other high-risk, third-party vendors.
−Removed: Chevron’s Chief Information Security Officer (CISO) leads a global cybersecurity team that operationalizes and manages the company’s cybersecurity program and strategy.
−Removed: Chevron’s CISO has more than 20 years of cybersecurity experience and is responsible for providing a single and consolidated view of the company’s enterprise cybersecurity risk.
−Removed: Before joining Chevron, he held a leadership role in cyber threat analysis with the U.S.
−Removed: Department of State’s Bureau of Diplomatic Security.
−Removed: Chevron’s CISO reports to the Chief Information Officer (CIO) who is responsible for Chevron’s broader IT program, including resiliency and ability to remediate and recover from a cybersecurity incident to minimize impacts to the business and operations.
−Removed: He has more than 30 years of experience in IT and the oil and gas industry.
+Added: Chevron’s Chief Information Officer (CIO) oversees Chevron’s broader IT program, which includes the company’s cybersecurity program and its ability to remediate and recover from a cybersecurity incident to minimize business and operational impacts.
+Added: Chevron’s CIO joined Chevron in 2024, bringing more than 20 years of experience leading global innovation initiatives in digital, data, full supply chains, vehicle commerce, energy, and IT operations for technology and automotive companies.
+Added: Chevron’s Chief Information Security Officer (CISO) reports to the CIO and leads a global cybersecurity team.
Chevron operates four Cyber Intelligence Centers around the world, some co-located with critical assets, with cyber professionals who monitor and respond to cyber threats 24 hours a day, 365 days a year, to limit the scope and impact of cyber incidents in its networks.
−Removed: Chevron’s CISO regularly receives cybersecurity operations reports detailing prevention, detection, mitigation and remediation efforts associated with cyber incidents, both on Chevron’s networks and third-party supplier networks.
−Removed: The CISO has authority to mobilize a cross-functional cyber incident response team, including outside cybersecurity experts, to drive mitigation and remediation actions.
+Added: The cybersecurity organization provides the IT leadership, which includes Chevron’s CIO, with regular cybersecurity operations reports detailing prevention, detection, mitigation and remediation efforts associated with cyber incidents, both on Chevron’s networks and third-party supplier networks.
+Added: The leadership of the cybersecurity organization has authority to mobilize a cross-functional cyber incident response team, including outside cybersecurity experts, to drive mitigation and remediation actions.
Status updates on incidents are provided to senior management and to the Board, as appropriate.
9 unchanged sentences
Chevron works to identify critical business processes and dependent IT applications and document the processes for continuing operations without IT systems.
−Removed: Cross-functional teams also conduct regular multidisciplinary exercises, including an expansive cybersecurity exercise in 2023, to test and improve response plans.
+Added: Cross-functional teams also conduct regular multidisciplinary exercises to test and improve response plans.
The Board provides oversight of Chevron’s cybersecurity program, receives reports from management on cybersecurity risks in connection with Chevron’s operations and projects, and also reviews cybersecurity risks as part of the company’s broader annual ERM process.
−Removed: In support of the Board’s oversight of the company’s policies and processes with respect to risk management and the company’s major financial risk exposures, including cybersecurity, the Audit Committee meets with Chevron’s CISO and CIO at least twice a year to review cybersecurity risks and implications, including the results of
−Removed: independent third-party assessments.
+Added: In support of the Board’s oversight of the company’s policies and processes with respect to risk management and the company’s major financial risk exposures, including cybersecurity, the Audit Committee meets with Chevron’s CISO and CIO at least twice a year to review cybersecurity risks and implications, including the results of independent third-party assessments.
The CISO and CIO present cybersecurity matters to the Board of Directors at least annually.
The CISO and CIO also provide new Board members with a cybersecurity briefing as part of the onboarding process.
−Removed: In 2023, the Audit Committee hosted an external expert to discuss cybersecurity and digital risk management topics.
To date, the company has not experienced a cybersecurity threat or incident that has materially affected or is reasonably likely to materially affect the company, including its business strategy, results of operations or financial condition;
4 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.