XML 78 R44.htm IDEA: XBRL DOCUMENT v3.25.0.1
Cybersecurity Risk Management and Strategy Disclosure
12 Months Ended
Dec. 31, 2024
Cybersecurity Risk Management, Strategy, and Governance [Line Items]  
Cybersecurity Risk Management Processes for Assessing, Identifying, and Managing Threats [Text Block]
Chevron’s business and proprietary information, information technology (IT) and operational technology (OT) networks are essential to its success. The company’s cybersecurity program is designed to protect its information assets and operations from external and internal cyber threats by identifying and appropriately managing and mitigating risks while ensuring business resiliency. This program is integrated within the company’s Enterprise Risk Management (ERM) process, which is the company’s systematic approach to identifying, managing and assessing major risks and safeguards, including cybersecurity risks. Chevron uses a risk-based information security process aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework to identify, prioritize and mitigate cyber risks.
The company’s worldwide team of cybersecurity professionals undertakes a range of preemptive activities to protect its people, assets and reputation globally. The company also leverages internal and external resources to monitor cybersecurity threats to its systems and networks and to understand the broader threat environment. The company seeks to remove exploitable weaknesses in its systems or devices before they become a threat. Chevron security experts use automated threat intelligence feeds to increase vulnerability awareness, taking action to mitigate the highest risks. The company’s cybersecurity guardrails, which are high-level design requirements expected to be built into any new digital solutions being deployed, are also updated on an ongoing basis to align with changes in industry standards and the evolving threat environment.
Chevron’s cyber risk management process includes testing and risk assessments of technologies, third-party suppliers, and its IT and OT networks. These assessments ensure that our focus is on the highest priorities to maintain the security of our company’s assets. To further protect the company’s systems and data, Chevron’s cybersecurity organization has threat intelligence capabilities to monitor security breaches impacting third-party suppliers. As third-party risks increase, the company’s approach to third-party supplier risk management and qualification continues to evolve, including the ongoing expansion of its current supplier risk management program beyond IT vendors to other high-risk, third-party vendors.
Cybersecurity Risk Management Processes Integrated [Flag] true
Cybersecurity Risk Management Processes Integrated [Text Block]
Chevron’s business and proprietary information, information technology (IT) and operational technology (OT) networks are essential to its success. The company’s cybersecurity program is designed to protect its information assets and operations from external and internal cyber threats by identifying and appropriately managing and mitigating risks while ensuring business resiliency. This program is integrated within the company’s Enterprise Risk Management (ERM) process, which is the company’s systematic approach to identifying, managing and assessing major risks and safeguards, including cybersecurity risks. Chevron uses a risk-based information security process aligned with the National Institute of Standards and Technology (NIST) Cybersecurity Framework to identify, prioritize and mitigate cyber risks.
The company’s worldwide team of cybersecurity professionals undertakes a range of preemptive activities to protect its people, assets and reputation globally. The company also leverages internal and external resources to monitor cybersecurity threats to its systems and networks and to understand the broader threat environment. The company seeks to remove exploitable weaknesses in its systems or devices before they become a threat. Chevron security experts use automated threat intelligence feeds to increase vulnerability awareness, taking action to mitigate the highest risks. The company’s cybersecurity guardrails, which are high-level design requirements expected to be built into any new digital solutions being deployed, are also updated on an ongoing basis to align with changes in industry standards and the evolving threat environment.
Cybersecurity Risk Management Third Party Engaged [Flag] true
Cybersecurity Risk Third Party Oversight and Identification Processes [Flag] true
Cybersecurity Risk Materially Affected or Reasonably Likely to Materially Affect Registrant [Flag] false
Cybersecurity Risk Board of Directors Oversight [Text Block]
Chevron’s Chief Information Officer (CIO) oversees Chevron’s broader IT program, which includes the company’s cybersecurity program and its ability to remediate and recover from a cybersecurity incident to minimize business and operational impacts. Chevron’s CIO joined Chevron in 2024, bringing more than 20 years of experience leading global innovation initiatives in digital, data, full supply chains, vehicle commerce, energy, and IT operations for technology and automotive companies. Chevron’s Chief Information Security Officer (CISO) reports to the CIO and leads a global cybersecurity team.
Chevron operates four Cyber Intelligence Centers around the world, some co-located with critical assets, with cyber professionals who monitor and respond to cyber threats 24 hours a day, 365 days a year, to limit the scope and impact of cyber incidents in its networks. The cybersecurity organization provides the IT leadership, which includes Chevron’s CIO, with regular cybersecurity operations reports detailing prevention, detection, mitigation and remediation efforts associated with cyber incidents, both on Chevron’s networks and third-party supplier networks. The leadership of the cybersecurity organization has authority to mobilize a cross-functional cyber incident response team, including outside cybersecurity experts, to drive mitigation and remediation actions. Status updates on incidents are provided to senior management and to the Board, as appropriate.
The company’s dedicated cyber risk organization meets regularly with business units to raise cyber risk awareness and keep diverse cybersecurity skill sets connected across the enterprise. Chevron has invested in broad cybersecurity awareness and required training to educate those with access to Chevron’s networks on company policy and best practices. The company conducts regular phishing tests to train and assess its workforce’s ability to identify malicious emails.
Chevron’s Corporate Audit Department has a dedicated team responsible for IT and information security (including cybersecurity) audits. Chevron also leverages external resources to reinforce its cybersecurity capabilities. On a regular basis, external consultants provide a maturity assessment of the company’s cybersecurity program.
The company’s approach to managing risks, including cybersecurity risks, is embedded within the enterprise Operational Excellence (OE) Management System (OEMS). The OEMS provides a systematic process that enables the company to manage risk and implement safeguards and foster a culture of learning across different focus areas for Chevron’s business, including cybersecurity. The company’s Business Continuity Planning OE Process, a component of the OEMS, is designed to prepare Chevron to continue operations during an unplanned event or disruption, which aligns with its OE objective to prevent high-consequence security and cybersecurity incidents. Chevron works to identify critical business processes and dependent IT applications and document the processes for continuing operations without IT systems. Cross-functional teams also conduct regular multidisciplinary exercises to test and improve response plans.
The Board provides oversight of Chevron’s cybersecurity program, receives reports from management on cybersecurity risks in connection with Chevron’s operations and projects, and also reviews cybersecurity risks as part of the company’s broader annual ERM process. In support of the Board’s oversight of the company’s policies and processes with respect to risk management and the company’s major financial risk exposures, including cybersecurity, the Audit Committee meets with Chevron’s CISO and CIO at least twice a year to review cybersecurity risks and implications, including the results of independent third-party assessments. The CISO and CIO present cybersecurity matters to the Board of Directors at least annually. The CISO and CIO also provide new Board members with a cybersecurity briefing as part of the onboarding process.
Cybersecurity Risk Board Committee or Subcommittee Responsible for Oversight [Text Block]
Chevron operates four Cyber Intelligence Centers around the world, some co-located with critical assets, with cyber professionals who monitor and respond to cyber threats 24 hours a day, 365 days a year, to limit the scope and impact of cyber incidents in its networks. The cybersecurity organization provides the IT leadership, which includes Chevron’s CIO, with regular cybersecurity operations reports detailing prevention, detection, mitigation and remediation efforts associated with cyber incidents, both on Chevron’s networks and third-party supplier networks. The leadership of the cybersecurity organization has authority to mobilize a cross-functional cyber incident response team, including outside cybersecurity experts, to drive mitigation and remediation actions. Status updates on incidents are provided to senior management and to the Board, as appropriate.
The company’s dedicated cyber risk organization meets regularly with business units to raise cyber risk awareness and keep diverse cybersecurity skill sets connected across the enterprise. Chevron has invested in broad cybersecurity awareness and required training to educate those with access to Chevron’s networks on company policy and best practices. The company conducts regular phishing tests to train and assess its workforce’s ability to identify malicious emails.
Chevron’s Corporate Audit Department has a dedicated team responsible for IT and information security (including cybersecurity) audits. Chevron also leverages external resources to reinforce its cybersecurity capabilities. On a regular basis, external consultants provide a maturity assessment of the company’s cybersecurity program.
The company’s approach to managing risks, including cybersecurity risks, is embedded within the enterprise Operational Excellence (OE) Management System (OEMS). The OEMS provides a systematic process that enables the company to manage risk and implement safeguards and foster a culture of learning across different focus areas for Chevron’s business, including cybersecurity. The company’s Business Continuity Planning OE Process, a component of the OEMS, is designed to prepare Chevron to continue operations during an unplanned event or disruption, which aligns with its OE objective to prevent high-consequence security and cybersecurity incidents. Chevron works to identify critical business processes and dependent IT applications and document the processes for continuing operations without IT systems. Cross-functional teams also conduct regular multidisciplinary exercises to test and improve response plans.
Cybersecurity Risk Process for Informing Board Committee or Subcommittee Responsible for Oversight [Text Block] The company’s approach to managing risks, including cybersecurity risks, is embedded within the enterprise Operational Excellence (OE) Management System (OEMS). The OEMS provides a systematic process that enables the company to manage risk and implement safeguards and foster a culture of learning across different focus areas for Chevron’s business, including cybersecurity. The company’s Business Continuity Planning OE Process, a component of the OEMS, is designed to prepare Chevron to continue operations during an unplanned event or disruption, which aligns with its OE objective to prevent high-consequence security and cybersecurity incidents. Chevron works to identify critical business processes and dependent IT applications and document the processes for continuing operations without IT systems. Cross-functional teams also conduct regular multidisciplinary exercises to test and improve response plans.
Cybersecurity Risk Role of Management [Text Block] The Board provides oversight of Chevron’s cybersecurity program, receives reports from management on cybersecurity risks in connection with Chevron’s operations and projects, and also reviews cybersecurity risks as part of the company’s broader annual ERM process. In support of the Board’s oversight of the company’s policies and processes with respect to risk management and the company’s major financial risk exposures, including cybersecurity, the Audit Committee meets with Chevron’s CISO and CIO at least twice a year to review cybersecurity risks and implications, including the results of independent third-party assessments. The CISO and CIO present cybersecurity matters to the Board of Directors at least annually. The CISO and CIO also provide new Board members with a cybersecurity briefing as part of the onboarding process.
Cybersecurity Risk Management Positions or Committees Responsible [Flag] true
Cybersecurity Risk Management Positions or Committees Responsible [Text Block] The Board provides oversight of Chevron’s cybersecurity program, receives reports from management on cybersecurity risks in connection with Chevron’s operations and projects, and also reviews cybersecurity risks as part of the company’s broader annual ERM process.
Cybersecurity Risk Management Expertise of Management Responsible [Text Block] Chevron’s CIO joined Chevron in 2024, bringing more than 20 years of experience leading global innovation initiatives in digital, data, full supply chains, vehicle commerce, energy, and IT operations for technology and automotive companies. Chevron’s Chief Information Security Officer (CISO) reports to the CIO and leads a global cybersecurity team.
Cybersecurity Risk Process for Informing Management or Committees Responsible [Text Block] the Audit Committee meets with Chevron’s CISO and CIO at least twice a year to review cybersecurity risks and implications, including the results of independent third-party assessments.
Cybersecurity Risk Management Positions or Committees Responsible Report to Board [Flag] true