NIST SP 800-53 Cross-Reference

Compliance
Security Management
IT Management
Cross-reference from the NIST SP 800-53 control families to the Tessera policies and controls that give effect to them. Provided as a supplementary mapping; the primary control framework is ISO/IEC 27001:2022.
Title NIST SP 800-53 Cross-Reference
Doc# DOC-COMPL-002
Version 1.1
Date 05-03-2025

This is a cross-reference from the NIST SP 800-53 control families to the Tessera policies and controls that address them. NIST SP 800-53 is a supplementary reference here, not the primary frame: Tessera’s information security management system is operated to ISO/IEC 27001:2022, with baseline hardening aligned to the ASD Essential Eight and the ASD Information Security Manual, and privacy obligations governed by the Privacy Act 1988 (Cth). The mapping is provided to help tenants and assessors who work in a NIST frame reconcile it with Tessera’s controls.

ID NIST SP 800-53 control family Tessera policies and controls
AC Access Control Access
AT Awareness and Training Roles and Responsibilities
AU Audit and Accountability Roles and Responsibilities; Compliance Audits
CA Security Assessment and Authorisation Risk Management; Access
CM Configuration Management Configuration and Change Management
CP Contingency Planning Business Continuity and Disaster Recovery
IA Identification and Authentication Access
IR Incident Response Incident Response; Breach Notification
MA Maintenance Configuration and Change Management
PE Physical and Environmental Protection Facility and Physical Security
PL Planning Security Programme Overview; Security Architecture & Operating Model
PS Personnel Security HR & Personnel Security
RA Risk Assessment Risk Management
SA System and Services Acquisition Third Party Security, Vendor Risk Management and Systems/Services Acquisition
SC System and Communications Protection Data Management; Data Protection; and Threat Detection & Prevention
SI System and Information Integrity Data Management; Data Protection; Product Security & Secure Software Development; Vulnerability Management; and System Audits, Monitoring & Assessments
PM Program Management Security Programme Overview; Roles and Responsibilities; and Policy Management

STALE REFERENCE: Several linked policy documents are being rationalised as part of certification-readiness, and a small number may be re-titled, consolidated or retired. Where a link does not resolve, the corresponding control is still addressed in the Statement of Applicability (DOC-SEC-003) and the risk treatment plan; treat this cross-reference as a guide rather than the authoritative control set.