Each of our brands has been increasing the penetration of 3D technology in its design
process and increasing its use of digital printing. The use of digital printing and laser finishing techniques across our brands reduces our reliance on resource-heavy traditional techniques and helps to reduce our environmental impact.
Information Security and Privacy
The Company has a comprehensive Cybersecurity Program that has been developed to align
with industry standards and best practices and that is designed to comply with currently applicable regulatory requirements. The Cybersecurity Program considers the full lifecycle of our information security. We employ the NIST Framework for
Improving Critical Infrastructure Cybersecurity to identify, manage and reduce our risks and protect our networks and data.
Our cybersecurity framework is actualized through the implementation of strong
security practices focused on continuous monitoring, threat evaluations and response protocols. The programs and policies we have established are designed to safeguard the Company and its stakeholders and to comply with the PCI Data Security
Standards and currently applicable regulatory obligations. We ensure that our programs address the use and security of the devices, systems, network and data of our associates, contractors, temporary staff and any others with authorized
access to our systems. We have established rules governing the use, retention, access, transmission and monitoring of electronic communication and sensitive information. We protect data privacy with authorization protocols, password
requirements, multi-factor authentication, encryption and other data loss prevention solutions.
We conduct routine security checks, perform upgrades and assess the integrity of our
systems through internal and third-party vulnerability and penetration tests and various tabletop exercises. We practice industry-standard data access and disclosure protections and environment segmentation to improve our protections and
limit data exposure in the event of a potential breach. We also reinforce our practices with regularly-scheduled associate training and awareness campaigns. The Company maintains cybersecurity insurance as part of its risk management process.
The Company has also implemented an incident reporting and response plan designed to address and remediate potential critical security incidents.
Our Technology Groups, which include the IT Security and Compliance departments, along
with supply chain and logistics, work with other departments and leaders, such as our General Counsel and our Chief Human Resources Officer, to support Company-wide compliance and awareness. The Board and its committees also serve an
important role in managing privacy and information security risks. The Board receives updates from senior management multiple times a year covering the Company’s cybersecurity strategy and current cyber trends. The Audit Committee also
oversees the adequacy and effectiveness of our information security and technology risk management policies and internal controls. Three members of our Board have expertise in IT and cybersecurity. These directors are Mr. Mansell, Ms. Kerr
and Mr. Mahoney.
We expect all of our associates to play an active role in maintaining the integrity
and security of our information systems and have robust privacy and information training requirements.
We also have ongoing training and awareness efforts that include anti-phishing
campaigns, company-wide alerts, training videos and published policies and standards.
Operationally Excellent
We approach our business through prudent management and oversight, acting with
integrity, a commitment to sustainable and ethical practices and with a focus on transparency and accountability.
Sustainable Operations
Our commitment to environmental sustainability extends beyond our supply chain and
merchandise to our own physical footprint. By examining how we rely on and use physical resources within our stores, distribution center and corporate headquarters, we are better positioned to actively identify ways to minimize our overall
impact and adopt more conscientious practices. Over the past few years, we have focused on the waste we produce, the energy we consume and the water we use.
These factors are managed by our operations and asset protection teams who oversee our
corporate headquarters, distribution center and store facilities. We also educate and encourage our associates to support our sustainability efforts in their everyday activities.
Ethics and Integrity
Our Code of Ethics and Global Vendor Code of Conduct form the basis of our day-to-day
expectations and serve as the minimum standards of ethical behavior. These policies are broad in scope, addressing matters such as conflicts of interests, fair dealing, bribery and fraud, employment laws, health and safety and environmental
protection.
Within the first 30 days, associates are required to complete six mandatory training
courses on areas that include our Code of Ethics, compliance, information and data security and proper conduct. Additional training is assigned on an as-needed basis, and can vary depending on an associate’s role and position. We require
annual retraining and certification to help reinforce our collective commitment to compliance, ethics and integrity.
Our executive team and Board set the tone and advise on our ethics and compliance
activities. Our Legal Department, under the guidance of our General Counsel, manages our ethics and compliance policies.
We provide an independent third-party operated Open Door and Ethics Hotline that is
available 24 hours, 7 days a week, 365 days a year and a Loss Prevention Hotline for anonymous reporting of any suspected activity or threatening situation. These channels, and others, are kept as confidential as possible and are supported by
our non-retaliation policy to safeguard those who make a report or who may participate in an investigation.
Philanthropy
The Company strives to positively impact our customers, associates and the communities
in which we live and do business through community service and giving back. Our brand and corporate cause-related initiatives are focused on raising awareness and funds through local, regional and national