XML 48 R29.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Cyber Risk Management & Strategy

As part of its overall risk management system, EOG regularly assesses its processes and practices for managing and mitigating cybersecurity risks and determines whether such risks are being effectively managed and mitigated.

EOG has invested in and implemented multiple technologies, controls, and procedures designed to protect its information systems and related infrastructure; identify, assess and remediate vulnerabilities; and monitor and mitigate the risk of data loss and other cybersecurity threats and intrusions.

EOG focuses on building cybersecurity awareness with its employees and other end-users through training and security exercises and communicates EOG's expectations of employees and contractors with respect to cybersecurity matters via EOG's Codes of Business Conduct and Ethics.
EOG's dedicated, in-house cybersecurity team, which is responsible for EOG's cybersecurity strategy and planning, oversees such efforts, with assistance from external threat analysts, consultants and service providers. As part of these efforts, such team seeks to identify potential cyber vulnerabilities and opportunities for improvement and then evaluates and implements different cybersecurity technologies to address any identified vulnerabilities and opportunities.

In addition, EOG's internal audit team, in conjunction with third-party experts, plays an important role in reviewing and assessing EOG's cybersecurity technologies, controls and procedures, including conducting penetration testing and vulnerability assessments.

In the event of an incident, EOG has a designated response team and written response plan in place with predefined escalation and response procedures. EOG also has processes in place to monitor the cybersecurity risk exposure and security practices of key service providers to assess their cyber preparedness.

While such technologies, controls, and procedures cannot entirely eliminate cybersecurity threats, EOG believes the risks from cybersecurity threats (including as a result of previous cybersecurity incidents) have been effectively managed and contained, and have not materially affected, and are not reasonably likely to materially affect, EOG and its business strategy, results of operations or financial condition. See ITEM 1A, Risk Factors, for related discussion.
As technology and potential cybersecurity threats evolve, EOG intends to continue to adapt and enhance its cybersecurity controls, procedures, and protections.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block] EOG has invested in and implemented multiple technologies, controls, and procedures designed to protect its information systems and related infrastructure; identify, assess and remediate vulnerabilities; and monitor and mitigate the risk of data loss and other cybersecurity threats and intrusions.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
EOG's cybersecurity team is led by EOG's group director, information systems and senior manager, information systems security, who each have over seven years of experience overseeing EOG's cybersecurity processes and strategy.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block] As part of its risk oversight responsibility and pursuant to its charter, the Audit Committee, in consultation with the Board and the Board's other committees, oversees EOG’s policies, strategies, and initiatives for mitigating cybersecurity and information technology risks.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block]
In the event of an incident, EOG has a designated response team and written response plan in place with predefined escalation and response procedures. EOG also has processes in place to monitor the cybersecurity risk exposure and security practices of key service providers to assess their cyber preparedness.
Cybersecurity Risk Role of Management [Text Block]
As discussed above, EOG's cybersecurity team consists of in-house cybersecurity professionals and external threat analysts, consultants and service providers. EOG's in-house professionals and external threat analysts possess various cybersecurity certifications.

EOG's cybersecurity team is led by EOG's group director, information systems and senior manager, information systems security, who each have over seven years of experience overseeing EOG's cybersecurity processes and strategy.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block]
EOG's cybersecurity team reports to EOG's Senior Vice President and Chief Information and Technology Officer, who has served as EOG's Chief Technology Officer since 2017 and as EOG's Chief Information Officer for over 25 years.

EOG's cybersecurity team leadership, Senior Vice President and Chief Information and Technology Officer and other members of senior management are responsible for the day-to-day management of cybersecurity risks and cybersecurity leadership. Such senior management team regularly reports to EOG's Audit Committee and Board of Directors (Board) regarding cybersecurity matters, including the assessments performed regarding EOG's cybersecurity technologies, controls and procedures.
As part of its risk oversight responsibility and pursuant to its charter, the Audit Committee, in consultation with the Board and the Board's other committees, oversees EOG’s policies, strategies, and initiatives for mitigating cybersecurity and information technology risks.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block]
EOG's cybersecurity team is led by EOG's group director, information systems and senior manager, information systems security, who each have over seven years of experience overseeing EOG's cybersecurity processes and strategy.
Cyber Governance & Oversight
EOG's cybersecurity team reports to EOG's Senior Vice President and Chief Information and Technology Officer, who has served as EOG's Chief Technology Officer since 2017 and as EOG's Chief Information Officer for over 25 years.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block]
In the event of an incident, EOG has a designated response team and written response plan in place with predefined escalation and response procedures. EOG also has processes in place to monitor the cybersecurity risk exposure and security practices of key service providers to assess their cyber preparedness.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true