Security Programme Overview
| Title | Security Programme Overview |
| Doc# | DOC-SECU-011 |
| Version | 1.1 |
| Date | 05-03-2025 |
Tessera’s security programme exists to protect the workforce, partners, tenants and the company itself from harmful acts — whether malicious or unintentional. It does this through a set of policies, standards, controls and procedures designed to preserve the confidentiality, integrity and availability of systems and data in proportion to their risk.
The programme rests on two principles: that security is everyone’s responsibility, and that the right behaviours are best encouraged by making them straightforward to follow. Quick Reference / Employee Handbook
Scope
The programme covers all Tessera workforce members — full-time and part-time employees, contractors, temporary staff, interns and managers — and the third parties granted access to Tessera systems or data. It is operated to ISO/IEC 27001:2022, aligned to the ASD Essential Eight, and meets Tessera’s obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. SOC 2 Type II is maintained in parallel; GDPR and sector schemes apply only where clients bring them into scope.
At a glance, the programme covers:
- Inventory and protection of critical assets.
- Visibility and management of the data lifecycle — creation, retention, deletion.
- Protection of data at rest, in transit and in use.
- Network architecture with enforced segmentation between control and data planes.
- Automated security configuration and remediation.
- Centralised identity and access management on a least-privilege baseline.
- Secure product development.
- Continuous monitoring, logging and auditing.
- Exercised plans for business continuity, disaster recovery and incident response.
- Endpoint protection and security awareness.
The programme is run by dedicated security and compliance staff under the CISO, using a governance, risk and compliance (GRC) platform to evidence controls and track corrective actions.
How the documents fit together
Each policy addresses a specific domain. Every document carries its version and last-updated date, followed by a summary and then its policy statements and the controls and procedures that give effect to them. Policy documents are maintained, reviewed and approved under Policy Management.
DRAFT NOTE: The policy suite is being rationalised as part of certification-readiness. Some legacy policy titles still in the document register are scheduled for re-titling or consolidation; cross-references will be updated as those land.
Review and reporting
The programme, its policies, procedures and controls are reviewed regularly — internally by cross-functional reviewers and externally by qualified assessors, including the ISO/IEC 27001:2022 certification body. Material findings, incidents and corrective actions are reported to the Executive Risk Committee.