Document Register

Document Management
Compliance
The Tessera document register is the controlled catalogue of policies, procedures and supporting documents — their current status, owner and version — maintained to support document control and the ISO/IEC 27001:2022 audit.
Title Document Register
Doc# DOC-COMP-006
Version 1.4
Date 06-03-2025

The document register is the controlled catalogue of Tessera’s policies, standard operating procedures and supporting documents. Its purpose is to give a single, current view of what each document is, who owns it, and which version is in force — so that the workforce, auditors and the certification body are all looking at the same artefacts. It underpins document control, supports the ISO/IEC 27001:2022 certification-readiness audit, and is maintained alongside the Statement of Applicability (DOC-SEC-003).

Documents are versioned and reviewed at least annually, or sooner where a material change or an incident requires it. The register is the index; the authoritative content lives in each linked document.

Policies

Document Number Policy Title
POL-DATA-000 GDPR Data Processing Addendum (EU clients)
POL-COMP-002 Compliance Audits and External Communications
POL-HR-001 Roles, Responsibilities, and Training
POL-SEC-001 Facility Access and Physical Security
POL-DATA-001 Data Protection
POL-SEC-002 Third Party Security, Vendor Risk Management
POL-SEC-003 Breach Investigation and Notification
POL-IT-001 Configuration and Change Management
POL-BCDR-001 Business Continuity and Disaster Recovery
POL-IT-002 Asset Management
POL-SEC-004 Incident Response
POL-IT-003 System Audits, Monitoring, and Assessments
POL-IT-004 Vulnerability Management
POL-IT-005 Mobile Device Security and Storage Media Management
POL-RISK-001 Risk Management
POL-DATA-002 Data Management Policy
POL-SEC-005 Threat Detection and Prevention
POL-HR-002 HR and Personnel Security
POL-PRIV-001 Cookie Policy
POL-MGMT-001 Policy Management
POL-DEV-001 Secure Software Development and Product Security
POL-SEC-006 Access Control
POL-PRIV-002 Privacy Policy
POL-PRIV-003 Privacy and Consent
POL-SEC-007 Security Architecture and Operating Model
POL-SEC-022 Acceptable Use Policy

Standard Operating Procedures

Document Number SOP Title
SOP-SEC-001 Service Interruption and Outage Response
SOP-DATA-001 Data Backup and Restoration
SOP-SEC-002 Security Incident Handling
SOP-IT-001 Change Management
SOP-HR-001 Onboarding New Employees
SOP-SEC-003 User Account Management
SOP-COM-001 Vendor Management
SOP-COM-002 Compliance Auditing
SOP-IT-002 Software Development Life Cycle (SDLC)
SOP-SEC-004 Access Control Management
SOP-SEC-005 Vulnerability Management
SOP-IT-003 Network Configuration and Maintenance
SOP-HR-002 Employee Exit Procedures
SOP-MKT-001 Customer Support Processes
SOP-FIN-001 Financial Reporting Procedures
SOP-SEC-006 Encryption and Key Management
SOP-DEV-001 Secure Software Deployment
SOP-COM-003 Handling Legal Requests
SOP-IT-004 IT Asset Management
SOP-SEC-007 Physical Security Checks
SOP-BCDR-001 Failover Runbook
SOP-PRIV-001 Notifiable Data Breaches (NDB) Playbook

Other Documents

Document Number Document Title
DOC-SEC-001 Risk Register
DOC-SEC-002 Tessera Information Security Management System
DOC-IT-001 Approved Software
DOC-COMPL-002 NIST Mappings
DOC-ORG-001 Org Chart
DOC-PROC-001 Approved Vendors
DOC-HR-001 Employee Handbook and Policy Quick Reference
DOC-COMPL-003 ISO27001 Prep
DOC-NET-001 Cloud-Native Architecture Diagram
DOC-SEC-003 Statement of Applicability (SoA)
DOC-SEC-004 Key Definitions
DOC-EDU-001 Training Register
DOC-BCDR-001 Business Impact Analysis
DOC-SEC-005 Security Incident Register

REGISTER HYGIENE: The phantom “GDPR Compliance” (POL-COMP-001) and “HIPAA Compliance” (POL-COMPL-001) entries have been removed — no policy files carry those numbers. The real GDPR artefact is the Data Processing Addendum (POL-DATA-000), retained for EU clients. The legacy “HIPPA Mappings” entry (DOC-COMPL-001) has been removed in line with the HIPAA-mapping cull; the NIST cross-reference (DOC-COMPL-002) remains. The policy suite is being rationalised as part of certification-readiness; treat remaining policy titles as provisional until the next revision.