Cybersecurity Conflict minerals Our approach to cybersecurity is comprehensive and we Our Board places emphasis on the identification and management AAR is committed to complying fully with the reporting requirements continue to invest in an integrated toolset that leverages event of cybersecurity risks. The Board and its committees receive periodic of the Securities and Exchange Commission (SEC) with respect to aggregation and correlation using machine learning techniques to reports from management of system vulnerabilities and security Conflict Minerals (as defined by the SEC). To that end, AAR and help us remain responsive to the ever-changing and challenging measures in effect to deter and mitigate threats that can lead to its manufacturing subsidiaries work with applicable suppliers to cybersecurity space. hacking, unauthorized access, or compromise. perform the necessary due diligence in determining the potential for Conflict Minerals in their supply chain and products. AAR and its Globally, our privacy model conforms to the GDPR (General Data Our key initiatives for calendar years 2021 and 2022 are ensuring manufacturing subsidiaries designed their due diligence program Protection Regulation) standard, the highest recognized standard the availability of systems and resources, managed through our in accordance with the Organization for Economic Cooperation with the most stringent regulations. Our SOX (Sarbanes-Oxley Act) comprehensive incident response plan and disaster recovery and and Development Due Diligence Guidance for Responsible Supply cybersecurity compliance program is designed to manage IT general business continuity plan. We are also focused on enhancing the Chains of Minerals from Conflict-Affected and High-Risk Areas. For and access controls. effectiveness of our third-party managed Security Operations Center more information, see our Conflict Minerals Policy on our website. by building our own internal Security Operation Center for greater Complying with government standards such as NIST (The National internal threat visibility. Institute of Standards and Technologies), CMMC (Cybersecurity Maturity Model Certification) and ITAR (International Traffic in Arms Political engagement Regulations) allows us to have a leading edge in our ability to pursue, win and deliver on new business opportunities. We participate in the political process through regular and constructive engagement with government officials and In addition to compliance, we place our greatest emphasis policymakers. This engagement includes making political on security, protecting our digital assets and monitoring our contributions, and by encouraging the civic involvement of its infrastructure. We have counter measures in place to identify and employees. AAR complies with applicable laws and regulations respond to potential security vulnerabilities. related to its participation in the political process. We also focus on confidentiality and integrity of information for Our Government Affairs Department is responsible for managing protection of data and to ensure information is reliable and correct. and coordinating AAR’s political participation. The Board of Directors is responsible for overseeing our lobbying activities and political contributions, and for reviewing annual contributions and lobbying AAR’s employees take an annual hour-long reports. AAR’s participation in the political process is governed by Security Awareness Training that is primarily our Political Participation, Lobbying, and Contributions Policy. For focused on information security, specifically more information, see Political Engagement on our website. social media usage, phishing emails and anti-virus protection. 43
ESG Report | AAR Page 43 Page 45