Security Programme Overview

Security Management
Compliance
Operational Security
Overview of the Tessera information security programme — its scope, the principles it is built on, and the control domains it covers, aligned to ISO/IEC 27001:2022 and the Privacy Act 1988 (Cth).
Title Security Programme Overview
Doc# DOC-SECU-011
Version 1.1
Date 05-03-2025

Tessera’s security programme exists to protect the workforce, partners, tenants and the company itself from harmful acts — whether malicious or unintentional. It does this through a set of policies, standards, controls and procedures designed to preserve the confidentiality, integrity and availability of systems and data in proportion to their risk.

The programme rests on two principles: that security is everyone’s responsibility, and that the right behaviours are best encouraged by making them straightforward to follow. Quick Reference / Employee Handbook

Scope

The programme covers all Tessera workforce members — full-time and part-time employees, contractors, temporary staff, interns and managers — and the third parties granted access to Tessera systems or data. It is operated to ISO/IEC 27001:2022, aligned to the ASD Essential Eight, and meets Tessera’s obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. SOC 2 Type II is maintained in parallel; GDPR and sector schemes apply only where clients bring them into scope.

At a glance, the programme covers:

  1. Inventory and protection of critical assets.
  2. Visibility and management of the data lifecycle — creation, retention, deletion.
  3. Protection of data at rest, in transit and in use.
  4. Network architecture with enforced segmentation between control and data planes.
  5. Automated security configuration and remediation.
  6. Centralised identity and access management on a least-privilege baseline.
  7. Secure product development.
  8. Continuous monitoring, logging and auditing.
  9. Exercised plans for business continuity, disaster recovery and incident response.
  10. Endpoint protection and security awareness.

The programme is run by dedicated security and compliance staff under the CISO, using a governance, risk and compliance (GRC) platform to evidence controls and track corrective actions.

How the documents fit together

Each policy addresses a specific domain. Every document carries its version and last-updated date, followed by a summary and then its policy statements and the controls and procedures that give effect to them. Policy documents are maintained, reviewed and approved under Policy Management.

DRAFT NOTE: The policy suite is being rationalised as part of certification-readiness. Some legacy policy titles still in the document register are scheduled for re-titling or consolidation; cross-references will be updated as those land.

Review and reporting

The programme, its policies, procedures and controls are reviewed regularly — internally by cross-functional reviewers and externally by qualified assessors, including the ISO/IEC 27001:2022 certification body. Material findings, incidents and corrective actions are reported to the Executive Risk Committee.