Roles, Responsibilities and Training
| Title | Roles, Responsibilities and Training |
| Doc# | POL-SECU-002 |
| Version | 1.0 |
| Date | 01-04-2023 |
| Owner | Isabella Ferreira, Chief Information Security Officer |
| Approved By | Henrik Larsson, Chief Executive Officer |
| ISO/IEC 27001:2022 | A.5.2 Information security roles and responsibilities; A.6.3 Information security awareness, education and training |
Security and compliance are everyone’s responsibility. Tessera expects every workforce member to take security and privacy seriously in their own role. Most security incidents begin at the endpoint — a compromised device, a social engineering attempt, a slip, or an insider. People are both the first line of defence and the most common point of failure, which is why training and clear accountability matter.
In this and related policy documents, “employees” and “workforce members” are used interchangeably to mean all full-time and part-time employees, contractors and subcontractors, volunteers, interns, managers and executives at Tessera.
The Chief Information Security Officer (CISO), Isabella Ferreira, is accountable for the information security program. The privacy function is led by the Head of Compliance, Margaux Dubois, who acts as Tessera’s privacy lead; she reports to the CISO on privacy risk and discharges Tessera’s obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Notifiable Data Breaches (NDB) scheme. Together the CISO and the Head of Compliance own the development, testing, implementation, training and oversight of Tessera’s security and privacy program. The CISO is appointed by and reports to the CEO.
A standing Security Committee is chaired by the CISO and includes the senior leadership team members responsible for delivery: Dr Sana Qureshi (CTO), Adrian Vasquez (CIO), Noah Bennett (Head of Engineering), Grace Sullivan (COO) and Anika Desai (Head of People).
Policy Statements
Tessera policy requires that:
A CISO must be appointed to lead the information security program, and a privacy lead (Head of Compliance) to lead the privacy program. Together they maintain the safeguards that protect the confidentiality, integrity and availability of Tessera and tenant data.
Security and privacy are the responsibility of all workforce members (employees, contractors, interns, managers and executives). All workforce members must:
Complete all required security and privacy training, including the annual Privacy Act / APP / NDB awareness training that is the default for all staff, security awareness, and any additional role-based training.
Follow all requirements in Tessera security policy and procedures, including access control and the acceptable use policy for end-user computing.
See something, say something: report all suspicious activity to the Security team without delay.
All workforce members must report non-compliance with Tessera policy to the CISO or delegate. Those who report violations in good faith will not be subject to intimidation, threats, coercion, discrimination or any other retaliation.
All workforce members must cooperate with law enforcement and legal investigations. Interfering with an investigation through wilful misrepresentation, omission of facts or threats against any person is strictly prohibited.
Workforce members found in breach of this policy are subject to sanctions.
Segregation of duties is maintained where applicable to preserve checks and balances, minimise conflicts of interest and remove single points of compromise in critical systems.
Controls and Procedures
Assignment of Roles and the Security Committee
The CISO (Isabella Ferreira) leads the information security program; the Head of Compliance (Margaux Dubois) leads the privacy program.
The Security Committee is chaired by the CISO. Members are the senior leaders accountable for delivery:
- Isabella Ferreira — CISO (chair)
- Dr Sana Qureshi — CTO
- Adrian Vasquez — CIO
- Noah Bennett — Head of Engineering
- Grace Sullivan — COO
- Anika Desai — Head of People
- Marcus Reid — Head of Infrastructure
[Reviewer, A. Desai, 2025-03: Marcus Reid left in late 2024 — his seat is vacant pending backfill. Update the membership before the next committee minutes are circulated.]
General Responsibilities of the CISO
The CISO and the security team are responsible for:
- Building and maintaining the security and privacy program to satisfy regulatory and contractual requirements.
- Establishing, documenting, distributing and updating security policies, standards and procedures.
- Overseeing, enforcing and documenting the activities that maintain compliance, and verifying they meet requirements.
- Monitoring, analysing, distributing and escalating security alerts and intelligence.
- Maintaining the security incident response and escalation procedures (see Incident Response Policy, POL-SECU-010) for timely and effective handling.
- Administering user accounts including joiner-mover-leaver changes, per the offboarding procedure ISMS-PR-014.
- Monitoring and controlling access to critical systems and data.
- Performing risk assessment, treatment and ongoing risk management (see Risk Management, POL-RISK-014).
- Delivering regular security awareness and compliance training, plus periodic updates and reminders for all workforce members.
- Operating a program that encourages the right behaviours, supports timely reporting and investigation of violations, applies practical mitigation, and imposes fair sanctions.
- Assisting with the administration of supplier agreements (see Vendor Risk Management, POL-RISK-005).
- Facilitating audits and assessments to validate compliance across the organisation.
- Working with the COO/CFO so that security objectives are properly resourced in the budgeting cycle.
Workforce Supervision Responsibilities
While the CISO owns the program, supervision of day-to-day compliance is everyone’s job — team leads, supervisors, managers and co-workers all oversee workforce members and other users of Tessera systems, applications, servers and workstations that hold sensitive data.
- Monitor workstations and applications for unauthorised use, tampering and theft, and report non-compliance under the Incident Response Policy (POL-SECU-010).
- Assist the CISO and Head of Compliance to ensure role-based access is provisioned correctly.
- Take reasonable steps to hire, retain and promote workforce members who comply with security policy, and to withdraw access promptly when someone leaves or changes role. Supervisors must report terminations and role changes to the Security team so access is revoked under the offboarding procedure ISMS-PR-014 (target: within 24 hours of termination).
Segregation of Duties
Tessera has dedicated personnel assigned to security and compliance. Separation of duties is achieved through a mix of role assignment and automation for software-defined processes.
Checks and balances are enforced through segregation of duties and the related review and approval processes. Where applicable, review and approval must come from a person other than the one who performed the work.
Policy and Compliance Training
The CISO and Head of Compliance facilitate training for all workforce members:
- New workforce members within their first month of employment;
- Existing workforce members annually;
- Existing workforce members whose functions are affected by a material change in policy, within a month of the change taking effect;
- Existing workforce members as needed due to changes in Tessera’s security or risk posture.
Records of training materials and attendees are retained for a minimum of seven years and held in the training register (see the Training register maintained by the CISO’s office).
Training covers, but is not limited to:
- The Tessera security and privacy program and its objectives;
- The Privacy Act 1988 (Cth), the Australian Privacy Principles (in particular APP 6, APP 11) and the NDB scheme — the default awareness training for all staff;
- Risk management procedures and documentation;
- Auditing and monitoring — Tessera may monitor the access and activity of all users;
- Acceptable use of workstations for assigned duties only;
- No downloading of software onto Tessera workstations or systems without prior approval from the CISO;
- Reporting malicious software to the CISO immediately;
- Reporting unauthorised attempts to use, or theft of, Tessera systems or workstations;
- Reporting unauthorised access to facilities;
- Reporting log-in discrepancies (for example, the application reports a last log-in on a date the user was on leave);
- No alteration of sensitive data held in a database unless authorised by the relevant Tessera tenant;
- Understanding one’s role in the BCDR plan (POL-RISK-008);
- No sharing of usernames or passwords with anyone;
- Requirements for creating and changing credentials;
- Setting all applications that hold or transmit sensitive data to log off after 15 minutes of inactivity;
- Supervisors reporting terminations and other leavers;
- Supervisors reporting changes to a user’s title, role, department or location;
- Procedures to back up sensitive data;
- Procedures to move and record movement of hardware and electronic media holding sensitive data;
- Procedures to dispose of discs, hard drives and other media holding sensitive data;
- Procedures to re-use electronic media holding sensitive data;
- Secrets management (for example SSH keys and access keys) and sensitive document encryption.
Ongoing Awareness Training
Tessera uses KnowBe4 to deliver monthly security awareness content to all employees. Modules cover:
- phishing,
- social engineering,
- safe internet use (social media, email, links),
- access control (passwords, MFA, screen locking),
- mobile device security,
- data protection, and
- system security (anti-malware, patching, secure configuration).
Progress is tracked per employee and reported through KnowBe4’s learning platform.
Privacy Act / APP / NDB Awareness Training
All employees complete Privacy Act / APP / NDB awareness training within 30 days of onboarding and annually thereafter. This is the default privacy training for all staff and reflects Tessera’s primary regulatory regime. The record is captured in the HR record and/or KnowBe4.
HIPAA Awareness Training (US-healthcare tenants only)
A small number of Tessera tenants are US healthcare providers. Workforce members who serve those tenants — identified by the Head of Compliance — complete additional HIPAA awareness training within 30 days of being assigned to a US-healthcare tenant and annually thereafter. HIPAA awareness is not a general requirement for all staff; it applies only where the role genuinely involves US protected health information. The record is captured in the HR record and/or KnowBe4.
[Reviewer, M. Dubois, 2025-02: the section heading above was previously “HIPAA Awareness Training” with no carve-out. This was a legacy of the combined Security-and-Privacy-Officer model; the default is now the Privacy Act / APP / NDB module. Make sure the joiner checklist (DOC-HR-001) reflects this.]
Internal Business Communications
Company-wide updates
Tessera holds a company-wide roundtable at least quarterly to communicate updates across operations, performance and objectives.
Senior management sends additional company-wide announcements through established internal channels such as email or the messaging platform (for example the #general channel).
Departmental, team and project updates
Each department, team and designated individual communicates performance and status updates through established channels.
Each project team maintains its own cadence and channel — for example daily development stand-ups or weekly team meetings.