KLA CORP 10-K Cybersecurity GRC - 2024-08-05

Page last updated on August 5, 2024

KLA CORP reported their cybersecurity risk management and governance process in a yearly 10-K filed on 2024-08-05 16:07:58 EDT.

Filings

10-K filed on 2024-08-05

KLA CORP filed a 10-K at 2024-08-05 16:07:58 EDT
Accession Number: 0000319201-24-000021

Note: filing items unformatted. Drop us a note with the above URL to help us prioritize formatting it!

Item 1C. Cybersecurity.

ITEM 1C. CYBERSECURITY Cybersecurity Risk Management and Strategy We have a cybersecurity risk management process intended to protect the confidentiality, integrity and availability of our critical systems and information. We design and assess our process based on the National Institute of Standards and Technology Cybersecurity Framework (“NIST CSF”). This does not imply that we meet any particular technical standards, specifications or requirements, only that we use the NIST CSF as a guide to help us identify, assess and manage cybersecurity risks relevant to our business. Our cybersecurity risk management process is integrated into our overall risk management process, and shares common methodologies, reporting channels and governance processes that apply across the risk management process to other legal, compliance, strategic, operational and financial risk areas. Key elements of our cybersecurity risk management process include, but are not limited to, the following: - Risk assessments designed to help identify material risks from cybersecurity threats to our critical systems and information; - A cybersecurity team principally responsible for managing (1) our cybersecurity risk assessment processes, (2) our security controls, and (3) our response to cybersecurity incidents; - The use of external service providers, where appropriate, to assess, test or otherwise assist with aspects of our security processes; - Cybersecurity awareness training of our workforce; - A cybersecurity incident response plan and processes for responding to cybersecurity incidents; and - Risk management processes based on our assessment of the respective risk profile of key third parties. We face risks from cybersecurity threats that, if realized, are reasonably likely to materially affect us, including our operations, business strategy, results of operations, or financial condition. See Part I Item 1A “Risk Factors - We depend on information technology for our business and are exposed to risks related to cybersecurity threats and cyber incidents affecting our, our customers’, suppliers’ and other service providers’ systems and networks. " Cybersecurity Governance Our Board considers cybersecurity risk as part of its risk oversight function and has delegated to the Audit Committee (the “Committee”) oversight of cybersecurity risks, including oversight of management’s implementation of our cybersecurity risk management process. The Committee receives quarterly reports from management on our cybersecurity risks. In addition, management updates the Committee, where it deems appropriate, regarding cybersecurity incidents it considers to be significant or potentially significant. The Committee reports to the full Board regarding its activities, including those related to cybersecurity. The full Board also regularly receives briefings from management on our cyber risk management process. Board members receive presentations on cybersecurity topics from management or external experts as part of the Board’s continuing education on topics that impact public companies. Our management team, including our Chief Legal Officer and Chief Information Security Officer (“CISO”), is responsible for assessing and managing our material risks from cybersecurity threats. The team has primary responsibility for our overall cybersecurity risk management process and supervises both our internal cybersecurity personnel and our retained external cybersecurity consultants. Our CISO has a degree with a focus on information technology, and is a Certified Information Systems Auditor with over 20 years of experience in information technology related roles, including building and leading cybersecurity, risk management and information protection teams. Our CISO reports to our Chief Legal Officer who oversees cybersecurity, and holds a Carnegie Mellon University Software Engineering Institute CERT Certificate for Cybersecurity Oversight. The other members of the operational cybersecurity team collectively have decades of relevant education and experience and maintain a wide range of industry certifications. We invest in regular, ongoing cybersecurity training for the cybersecurity team. Our management team takes steps to stay informed about and monitor efforts to prevent, detect, mitigate and remediate cybersecurity risks and incidents through various means, which may include: briefings from internal security personnel; threat intelligence and other information obtained from governmental, public or private sources, including external consultants engaged by us; and alerts and reports produced by security tools deployed in our information technology environment.


Company Information

NameKLA CORP
CIK0000319201
SIC DescriptionOptical Instruments & Lenses
TickerKLAC - Nasdaq
Website
CategoryLarge accelerated filer
Fiscal Year EndJune 29