|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|The Managing Owner has written procedures and policies that govern the Trust’s general cybersecurity program. These policies and procedures include, among other things, the identification of risks, locations of information, management of third party risk and incident response, among other factors, and are designed to address real world concerns.
The Cybersecurity Committee (the “Committee”) of the Managing Owner is responsible for overseeing cyber and information security. The Committee meets at least quarterly to discuss cybersecurity risks and frequently holds more informal discussions in the interim. The Committee is subject to oversight by the board of directors of the Managing Owner (the “Board”). The Committee is co-chaired by the Managing Owner’s President/Chief Operating Officer, Chief Technology Officer/Co-Head of Trading, and General Counsel/Chief Compliance Officer who oversee day-to-day implementation of cyber and information security by employees with specialized expertise and experience in such matters. The Board is kept apprised of the cybersecurity policies and procedures on a formal basis at least annually, and is kept informed on a less formal basis through participation in training and policy updates. The Committee meets at least quarterly to discuss and review testing, cybersecurity risks/events and all other relevant matters. Committee members are given the opportunity at these meetings to ask questions of all relevant personnel.
The Managing Owner utilizes a combination of statistics, data and testing by third party service providers and software in order to monitor and identify cybersecurity threats. To the extent those threats require immediate attention, they are dealt with and reported to the Committee thereafter in accordance with the procedures outlined in the Managing Owner’s incident response plan. Other threats, as well as follow ups once threats are properly dealt with, are then discussed and analyzed by the Committee. Reports on these activities are discussed with the Board on at least an annual basis, with any material issues raised promptly to the Board as well.
To assess the effectiveness of the Managing Owner’s cybersecurity programs and to mitigate exposure, the Managing Owner has consulted with strategic partners, such as outside counsel specializing in this subject matter as well as the Managing Owner’s cyber insurance provider. The Managing Owner also undertook a table top exercise designed to identify and mitigate issues and train personnel.
The Managing Owner’s head of risk management (who is also mentioned above as one of the co-chairmen of the Committee) participates in all Committee meetings and, as part of the risk management function, the Committee applies principles of risk management to its information security program. As with all risks identified by the Managing Owner, risks are identified and evaluated, with higher risk items receiving priority attention.
The Managing Owner has undertaken efforts to mitigate cyber risks and their impact, including, but not limited to, certain implementation of firewalls, anti-virus/anti-malware, controls around remote network access, multi-factor authentication, system event monitoring and notifications and electronic surveillance, frequent backups, encryption and password protection, education and testing, supervision of third parties, limitations on access, vulnerability scanning, patch installation, physical safeguards, virus scanning, and penetration testing.
Employees are required to complete initial cybersecurity training upon commencement of employment and, thereafter, on an annual basis. The training is designed by a third party service provider. The Managing Owner carries cyber insurance. The Managing Owner maintains formal cybersecurity procedures that are considered during contract review with respect to third party vendors handling and having access to information.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|To assess the effectiveness of the Managing Owner’s cybersecurity programs and to mitigate exposure, the Managing Owner has consulted with strategic partners, such as outside counsel specializing in this subject matter as well as the Managing Owner’s cyber insurance provider. The Managing Owner also undertook a table top exercise designed to identify and mitigate issues and train personnel.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Text Block]
|Reports on these activities are discussed with the Board on at least an annual basis, with any material issues raised promptly to the Board as well.
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|The Committee is subject to oversight by the board of directors of the Managing Owner (the “Board”).
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Cybersecurity Committee (the “Committee”) of the Managing Owner is responsible for overseeing cyber and information security. The Committee meets at least quarterly to discuss cybersecurity risks and frequently holds more informal discussions in the interim.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The Committee is co-chaired by the Managing Owner’s President/Chief Operating Officer, Chief Technology Officer/Co-Head of Trading, and General Counsel/Chief Compliance Officer who oversee day-to-day implementation of cyber and information security by employees with specialized expertise and experience in such matters. The Board is kept apprised of the cybersecurity policies and procedures on a formal basis at least annually, and is kept informed on a less formal basis through participation in training and policy updates. The Committee meets at least quarterly to discuss and review testing, cybersecurity risks/events and all other relevant matters. Committee members are given the opportunity at these meetings to ask questions of all relevant personnel.
|Cybersecurity Risk Role of Management [Text Block]
|The Managing Owner’s head of risk management (who is also mentioned above as one of the co-chairmen of the Committee) participates in all Committee meetings and, as part of the risk management function, the Committee applies principles of risk management to its information security program. As with all risks identified by the Managing Owner, risks are identified and evaluated, with higher risk items receiving priority attention.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|The Committee is co-chaired by the Managing Owner’s President/Chief Operating Officer, Chief Technology Officer/Co-Head of Trading, and General Counsel/Chief Compliance Officer who oversee day-to-day implementation of cyber and information security by employees with specialized expertise and experience in such matters.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|The Committee meets at least quarterly to discuss cybersecurity risks and frequently holds more informal discussions in the interim.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|The Board is kept apprised of the cybersecurity policies and procedures on a formal basis at least annually, and is kept informed on a less formal basis through participation in training and policy updates. The Committee meets at least quarterly to discuss and review testing, cybersecurity risks/events and all other relevant matters. Committee members are given the opportunity at these meetings to ask questions of all relevant personnel.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|false
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef