Acceptable Use Policy
| Title | Acceptable Use Policy |
| Doc# | POL-SEC-022 |
| Version | 1.0 |
| Date | 10-03-2025 |
| Owner | Chief Information Security Officer |
| Approved By | Head of People (A. Desai) / CIO (A. Vasquez) |
| ISO/IEC 27001:2022 | A.5.10 — Acceptable use of information and other associated assets |
1. Purpose and scope
This policy sets out the acceptable and prohibited uses of Tessera information systems, networks, devices, accounts and services (“Tessera Resources”). It applies to all workforce members, contractors, consultants, interns and authorised third parties who are granted access to Tessera Resources, whether accessed from Tessera premises, remotely, or from Tessera-managed or bring-your-own devices. It is issued as a standalone control to satisfy Annex A control A.5.10 of ISO/IEC 27001:2022.
PROVENANCE NOTE: Acceptable-use requirements were previously embedded only within the Employee Handbook (DOC-HR-001). They are now issued as a standalone, version-controlled policy so that the obligation extends to contractors and third parties who do not receive the Handbook. Some Handbook cross-references may still point to the old embedded section until the Handbook is updated.
2. Personal information and Australian privacy
Tessera holds personal information within the meaning of the Privacy Act 1988 (Cth) and must handle it in accordance with the Australian Privacy Principles (APPs), in particular APP 6 (use and disclosure) and APP 11 (security of personal information). Workforce members must access, use and disclose personal information only as required for their role and must report any actual or suspected unauthorised access or disclosure to the Security team without delay (see NDB Playbook, SOP-PRIV-001).
3. Acceptable use
Workforce members may use Tessera Resources for authorised business purposes and for incidental personal use that is reasonable, lawful, does not interfere with their duties, and does not consume disproportionate resources.
In using Tessera Resources, workforce members must:
authenticate using their own unique credentials and never share accounts, passwords, tokens, MFA factors or access keys;
comply with the least-privilege principle and use Tessera Resources only within the scope of their authorised role;
protect Tessera Resources in accordance with the Data Protection Policy and Data Classification Policy;
keep Tessera-managed devices updated and within the management envelope (endpoint agent, encryption, screen lock);
use only Tessera-approved cloud, AI and software services for Tessera or tenant information (see the Approved Software list, DOC-IT-001).
4. Prohibited use
The following are expressly prohibited:
using Tessera Resources to access, store or transmit unlawful, offensive or harassing material;
attempting to circumvent authentication, logging, monitoring or security controls, or probing/scanning systems without authorisation;
installing unauthorised software, including unapproved AI tools or browser extensions, on Tessera-managed devices;
entering Tessera or tenant information — including source code, credentials or personal information — into unapproved third-party or public AI services or public source-code repositories;
connecting unauthorised devices to production networks or tenant data stores;
using Tessera Resources for personal commercial activity, cryptocurrency mining, or any activity that brings Tessera into disrepute.
IMPLEMENTATION GAP: The prohibition in 4(d) on entering information into unapproved AI services is not yet technically enforced (no egress DLP rule for public LLM endpoints). It relies on workforce awareness until the DLP rollout completes.
5. AI services and generative tools
Tessera operates two approved AI capabilities: an internal AI summarisation service and a support AI assistant. Workforce members may use these approved services within their role. Use of any other generative-AI service with Tessera or tenant information requires approval and must follow the Approved Software process. Tenant information must not be submitted to any AI service that has not been assessed for privacy and data-handling.
6. Monitoring and privacy
Tessera monitors the use of Tessera Resources for security, operational and compliance purposes, including logging of authentication, network and cloud control-plane activity (for example, AWS CloudTrail). Monitoring is conducted in accordance with the Privacy Act and applicable workplace surveillance law. Workforce members should have no expectation of privacy in their use of Tessera Resources beyond that provided by law.
7. Reporting obligations
Workforce members must promptly report:
lost or stolen devices or credentials;
suspected phishing, malware or unauthorised access;
any actual or suspected privacy breach affecting personal information.
Reports should be made to security@tessera.locoensayo.org or via the IT support channel. Good-faith reports will not result in retaliation.
8. Enforcement
Non-compliance with this policy may result in withdrawal of access and disciplinary action up to and including termination of employment or contract, in accordance with the HR and Personnel Security Policy (POL-HR-002). Serious breaches may be referred to law enforcement.
9. Review
This policy is reviewed at least annually and after any significant incident or change to the threat landscape. The next scheduled review is 10-03-2026.