|
Cybersecurity Risk Management and Strategy Disclosure
|12 Months Ended
Dec. 31, 2024
|Cybersecurity Risk Management, Strategy, and Governance [Line Items]
|Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
|
The Company maintains a cybersecurity program that establishes safeguards for protecting the confidentiality, integrity, and availability of the Company’s data, technology, and information systems, and the material risks associated with the threats identified from time to time under the cybersecurity program are incorporated into the Company’s corporate risk register. The program includes general controls for managing changes in and access to the Company’s information technology environment, cybersecurity awareness and training programs to help employees identify and mitigate against cybersecurity threats, cybersecurity incident response plans and third-party incident response retainers to help expedite the Company’s response in the event of a cybersecurity incident, and guidelines regarding system vulnerability management, third-party threat intelligence, endpoint detection and response solutions, and network security measures.
The program also establishes protocols for identifying and managing material risks related to cybersecurity threats associated with the Company’s use of third-party service providers. The Company monitors and oversees the material risks related to vulnerabilities, threats, and incidents impacting its third-party service providers via onboarding reviews, threat intelligence reports, and annual assessments. As an example of the Company’s efforts to manage third-party cybersecurity risks, when third parties are engaged to provide software-as-a-service offerings, the Company’s standard licensing terms require such third parties to utilize safeguards to protect the Company’s data, in compliance with applicable standards from the International Organization for Standardization (ISO) regarding security techniques, and to notify the Company within 24 hours of becoming aware of a cybersecurity incident impacting the Company’s data.
|Cybersecurity Risk Management Processes Integrated [Flag]
|true
|Cybersecurity Risk Management Processes Integrated [Text Block]
|The Company maintains a cybersecurity program that establishes safeguards for protecting the confidentiality, integrity, and availability of the Company’s data, technology, and information systems, and the material risks associated with the threats identified from time to time under the cybersecurity program are incorporated into the Company’s corporate risk register.
|Cybersecurity Risk Management Third Party Engaged [Flag]
|true
|Cybersecurity Risk Third Party Oversight and Identification Processes [Flag]
|true
|Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag]
|false
|Cybersecurity Risk Board of Directors Oversight [Text Block]
|
The standing Cybersecurity Committee of the Company’s Board of Directors assists with oversight of the Company’s cybersecurity program and the material risks associated with the threats identified under the program. Given the Cybersecurity Committee’s chair’s previous military experience in positions relevant to information security and his NACD-sponsored CERT Certificate in Cybersecurity Oversight from Carnegie Mellon University’s Software Engineering Institute, the committee benefits from his perspectives, skills, and training when reviewing and managing the Company’s exposure to cybersecurity risks.
|Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
|The standing Cybersecurity Committee of the Company’s Board of Directors assists with oversight of the Company’s cybersecurity program and the material risks associated with the threats identified under the program.
|Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
|Board of Directors
|Cybersecurity Risk Role of Management [Text Block]
|
The Cybersecurity Committee reports regularly to the full Board of Directors, with respect to such matters as are relevant to the committee’s discharge of its responsibilities and with respect to such recommendations as the committee deems appropriate for consideration by the Board of Directors. The Cybersecurity Committee also refers to the Audit Committee any matters that come to the attention of the Cybersecurity Committee that fall within the purview of the Audit Committee, including any matters related to the Company’s internal control over financial reporting.
APA’s Executive Vice President, Administration, is primarily responsible for identifying, assessing, and managing the material risks associated with cybersecurity threats and the incidents identified from time to time thereunder. He manages the Company’s Information Security Team, which comprises cybersecurity professionals responsible for the day-to-day operation of the Company’s cybersecurity program and managing the Company’s threat intelligence, vulnerability management, forensics, and security architecture systems. APA’s Executive Vice President, Administration, has 35 years of experience managing data and technology in the energy industry, including serving as the Company’s CIO from 2015-2020. He receives regular updates from external cybersecurity specialists on emerging trends, threats, and technologies in the cybersecurity industry. The Executive Vice President, Administration, reports directly to APA’s Chief Executive Officer and presents all relevant information to the Cybersecurity Committee.
|Cybersecurity Risk Management Positions or Committees Responsible [Flag]
|true
|Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
|
The Cybersecurity Committee reports regularly to the full Board of Directors, with respect to such matters as are relevant to the committee’s discharge of its responsibilities and with respect to such recommendations as the committee deems appropriate for consideration by the Board of Directors. The Cybersecurity Committee also refers to the Audit Committee any matters that come to the attention of the Cybersecurity Committee that fall within the purview of the Audit Committee, including any matters related to the Company’s internal control over financial reporting.
|Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
|APA’s Executive Vice President, Administration, has 35 years of experience managing data and technology in the energy industry, including serving as the Company’s CIO from 2015-2020. He receives regular updates from external cybersecurity specialists on emerging trends, threats, and technologies in the cybersecurity industry. The Executive Vice President, Administration, reports directly to APA’s Chief Executive Officer and presents all relevant information to the Cybersecurity Committee.
|Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
|
The Cybersecurity Committee receives regular reports from Company management regarding the Company’s cybersecurity systems and programs, and the committee from time to time also receives updates from external cybersecurity specialists on cybersecurity trends and incidents, including those that may be particularly relevant to the Company’s industry or operations. In addition, in exercising its oversight responsibilities, the Cybersecurity Committee has full access to Company management and may inquire into any matter that it considers to be of material concern to the committee or the full Board of Directors.
|Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag]
|true
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef
|X
- References
+ Details
Reference 1: http://www.xbrl.org/2003/role/presentationRef