XML 59 R36.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Cybersecurity, resilience and data privacy are important to maintaining our proprietary information and the trust of our customers, suppliers and employees, and we recognize the importance of working to secure our data and information systems from potential cybersecurity and data privacy incidents. We are a large global manufacturer with sites around the world, and we identify and assess our cybersecurity risk through that lens. Securing the execution and control of our manufacturing operations, to the extent implemented through digital technology, is a primary area of focus. We also face risks encountered by substantially all large global companies such as the risks of intellectual property and information being compromised, fraud, business interruption and violation of privacy or security laws.
We identify, assess, manage and mitigate cybersecurity risk through a risk management program based on the NIST Cybersecurity Framework that is regularly assessed by a third party cybersecurity consultant. As part of our processes, we perform routine scanning and have an established vulnerability management program and patching policy. We have in our learning management system a comprehensive cybersecurity awareness course that is mandatory for all employees with computers and covers key topics such as identifying workplace cybersecurity hazards and attacks, and our separate CyberSAFE and Data Privacy intranets provide content to help employees identify and avoid cybersecurity and data privacy risks. We also have data privacy educational tools, policies and procedures to help employees prevent, recognize and report data privacy incidents. We perform penetration tests and vulnerability and breach assessments with third-party advisors to support our compliance with laws and regulations including those applicable to chemical manufacturing sites. We also have a third-party risk management program with a formal approach to evaluating and managing risks associated with third-party information technology solutions and software. We maintain cyber/information security insurance to protect against certain expenses and liabilities that may be incurred in the event of an incident.
Cybersecurity, resilience and data privacy risks are maintained and managed on an ongoing basis as part of our broader enterprise risk management program. Specifically, a risk management workstream focused on our information technology function (including cybersecurity, resilience and data privacy) is designed to assess, identify and manage cybersecurity- resilience and data privacy-related risks and mitigation measures.
Our cybersecurity risk program also includes a documented incident response plan to be used in the event of a cybersecurity incident. The incident response plan provides for certain responses based on various factors of a cybersecurity incident and integrates with our enterprise crisis management program.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Cybersecurity, resilience and data privacy are important to maintaining our proprietary information and the trust of our customers, suppliers and employees, and we recognize the importance of working to secure our data and information systems from potential cybersecurity and data privacy incidents. We are a large global manufacturer with sites around the world, and we identify and assess our cybersecurity risk through that lens. Securing the execution and control of our manufacturing operations, to the extent implemented through digital technology, is a primary area of focus. We also face risks encountered by substantially all large global companies such as the risks of intellectual property and information being compromised, fraud, business interruption and violation of privacy or security laws.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Primary responsibility for assessing and managing risks from cybersecurity threats resides with our management team, including a Chief Information Officer who has nearly 30 years of information technology experience including leadership roles at multiple large, global and/or publicly-traded companies, and a Chief Information Security Officer who has over 30 years of experience in cybersecurity with large international publicly-traded companies and who holds a Certified Information Systems Security Professional (CISSP) certification. These individuals, together with others on their teams, are informed about the monitoring, prevention, detection, mitigation, and remediation of cybersecurity incidents through their management of and participation in the cybersecurity risk management policies, processes and operations discussed above. They regularly report to and consult with the executive leadership team on such matters.
At the Board level, the full Board and its Stewardship Committee (which oversees many of our operational risks related to manufacturing) are both involved in oversight of the Company's management of cybersecurity risk. Management, including the Chief Information Officer and Chief Information Security Officer, updates our Stewardship Committee and full Board on cybersecurity matters quarterly. We also have processes by which certain cybersecurity incidents are escalated within the Company and may be reviewed by a designated management committee and, where appropriate, reported in a timely manner to the Board.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] Management, including the Chief Information Officer and Chief Information Security Officer, updates our Stewardship Committee and full Board on cybersecurity matters quarterly.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
Primary responsibility for assessing and managing risks from cybersecurity threats resides with our management team, including a Chief Information Officer who has nearly 30 years of information technology experience including leadership roles at multiple large, global and/or publicly-traded companies, and a Chief Information Security Officer who has over 30 years of experience in cybersecurity with large international publicly-traded companies and who holds a Certified Information Systems Security Professional (CISSP) certification. These individuals, together with others on their teams, are informed about the monitoring, prevention, detection, mitigation, and remediation of cybersecurity incidents through their management of and participation in the cybersecurity risk management policies, processes and operations discussed above. They regularly report to and consult with the executive leadership team on such matters.
At the Board level, the full Board and its Stewardship Committee (which oversees many of our operational risks related to manufacturing) are both involved in oversight of the Company's management of cybersecurity risk. Management, including the Chief Information Officer and Chief Information Security Officer, updates our Stewardship Committee and full Board on cybersecurity matters quarterly. We also have processes by which certain cybersecurity incidents are escalated within the Company and may be reviewed by a designated management committee and, where appropriate, reported in a timely manner to the Board.
Cybersecurity Risk Role of Management [Text Block] These individuals, together with others on their teams, are informed about the monitoring, prevention, detection, mitigation, and remediation of cybersecurity incidents through their management of and participation in the cybersecurity risk management policies, processes and operations discussed above. They regularly report to and consult with the executive leadership team on such matters.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] Management, including the Chief Information Officer and Chief Information Security Officer
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Primary responsibility for assessing and managing risks from cybersecurity threats resides with our management team, including a Chief Information Officer who has nearly 30 years of information technology experience including leadership roles at multiple large, global and/or publicly-traded companies, and a Chief Information Security Officer who has over 30 years of experience in cybersecurity with large international publicly-traded companies and who holds a Certified Information Systems Security Professional (CISSP) certification.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
Primary responsibility for assessing and managing risks from cybersecurity threats resides with our management team, including a Chief Information Officer who has nearly 30 years of information technology experience including leadership roles at multiple large, global and/or publicly-traded companies, and a Chief Information Security Officer who has over 30 years of experience in cybersecurity with large international publicly-traded companies and who holds a Certified Information Systems Security Professional (CISSP) certification. These individuals, together with others on their teams, are informed about the monitoring, prevention, detection, mitigation, and remediation of cybersecurity incidents through their management of and participation in the cybersecurity risk management policies, processes and operations discussed above. They regularly report to and consult with the executive leadership team on such matters.
At the Board level, the full Board and its Stewardship Committee (which oversees many of our operational risks related to manufacturing) are both involved in oversight of the Company's management of cybersecurity risk. Management, including the Chief Information Officer and Chief Information Security Officer, updates our Stewardship Committee and full Board on cybersecurity matters quarterly. We also have processes by which certain cybersecurity incidents are escalated within the Company and may be reviewed by a designated management committee and, where appropriate, reported in a timely manner to the Board.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true