Defines the acceptable and prohibited uses of Tessera information systems, devices and services by all workforce members, contractors and authorised third parties.
Defines how access to Tessera systems and information is granted, reviewed and revoked on a least-privilege basis, in line with APP 11 of the Privacy Act 1988 (Cth) and…
Lists the software approved for installation and use on Tessera endpoints and in the Tessera environment.
Lists the vendors approved for use across Tessera, with the service each provides and the basis of approval.
Describes how Tessera inventories and manages physical and digital assets, aligned to ISO/IEC 27001:2022 A.5.9, A.5.10 and A.5.14.
The Tessera Business Continuity and Disaster Recovery (BCDR) plan sets out how the platform is recovered and restored after a disruption.
Defines how Tessera investigates suspected data breaches and notifies the Office of the Australian Information Commissioner (OAIC) and affected individuals under the Privacy…
Tessera data classification policy establishes a systematic approach to categorising information assets based on their sensitivity, criticality, and regulatory requirements…
This policy sets out how Tessera manages the end-to-end data lifecycle for its own information and for tenant data held on the platform, from creation and acquisition…
How Tessera protects the confidentiality, integrity, and availability of tenant and corporate data across its production and corporate systems.
Defines the document numbering system used for Tessera policy, procedure and reference documents.
Sets out physical access and security controls for Tessera’s Perth, Sydney and Malaga offices, aligned to ISO/IEC 27001:2022 Annex A.7.
This Data Protection Addendum (this “Addendum”) is made and entered into as of the date appearing on the signature page hereto (the “Effective Date”) by and between Tessera…
Sets out how Tessera screens, onboards, trains, manages and offboards workforce members in line with ISO/IEC 27001:2022 Annex A.6 and the Privacy Act 1988.
Tessera’s Incident Response Policy defines how the security function prepares for, detects, triages, contains, eradicates and recovers from information security incidents…
Sets the mandatory configuration baseline for Microsoft Office macro settings on Tessera-managed endpoints, in line with APP 11 of the Privacy Act 1988 (Cth) and ISO/IEC…
Defines how Tessera identifies, assesses, patches and remediates technical vulnerabilities across applications and operating systems, in line with APP 11 of the Privacy Act…
Describes how Tessera develops, versions, approves, publishes and retires policy documents, and the compliance drivers they implement.
How Tessera collects, uses, holds and discloses personal information as an APP entity under the Privacy Act 1988 (Cth). External-facing Privacy Policy.
Internal policy on how Tessera collects, notifies, uses, secures and handles personal information under the Australian Privacy Principles, and the relationship to the…
This policy establishes the scope, objectives and procedures of Tessera’s information security risk management process.
Defines information security roles, responsibilities and training across Tessera.
Describes the security architecture and operating model that underpin the Tessera platform and internal environment.
Sets out how Tessera assesses and manages the security and privacy risk of suppliers, cloud services and acquired systems.
Defines the mandatory hardening baseline for user applications and the standard operating environment on Tessera-managed endpoints, in line with APP 11 of the Privacy Act…