| Title |
Training Register |
| Doc# |
DOC-EDU-001 |
| Version |
1.2 |
| Date |
05-03-2025 |
| Owner |
Head of People (A. Desai) |
The Training Register records the security, privacy and role-based training completed by the Tessera workforce. It supports control A.6.3 (Information security awareness, education and training) of ISO/IEC 27001:2022 and is a primary input to the certification-readiness audit. Training is completed on induction and refreshed annually, with targeted sessions off the back of incidents and policy changes. Completion is evidenced here and held against each individual’s record.
Security and privacy training
| I. Ferreira |
CISO |
Information Security Awareness (annual) |
12-02-2025 |
Online module |
Access control, phishing, incident reporting, APP 11 |
| M. Dubois |
Head of Compliance |
Privacy Act & APPs for practitioners |
20-02-2025 |
Workshop |
APP obligations, NDB scheme, serious-harm assessment |
| R. Costa |
Cloud Service Operations |
Cloud security operations on AWS |
18-02-2025 |
Online lab |
IAM least privilege, CloudTrail/GuardDuty, key handling |
| N. Bennett |
Head of Engineering |
Secure development & product security |
03-02-2025 |
Workshop |
Secure coding, secret management, CI security gates |
| C. Hayes |
Cloud Infrastructure Architect |
AWS secure architecture |
10-02-2025 |
Online lab |
VPC segmentation, KMS, row-level security, IAM roles |
| H. Boyd |
Head of IT |
Endpoint & identity security |
24-02-2025 |
Online module |
EDR, MFA, joiner/mover/leaver, device encryption |
Incident-driven training (post TSR-INC-2025-031)
| All engineering & cloud ops |
Static-key elimination & secret scanning |
10-03-2025 |
Live session |
Why static keys are a defect; pre-commit scanning; rotation |
| All workforce |
Phishing & credential hygiene refresher |
12-03-2025 |
Online module |
Recognising credential-theft lures; reporting |
Ethics and conduct
| A. Desai |
Head of People |
Business ethics & compliance |
28-01-2025 |
Online module |
REVIEWER NOTE: Annual security-awareness completion for the wider workforce is recorded in the learning-management system rather than listed individually here. The LMS export should be sampled during the audit to confirm coverage and timeliness, especially for joiners and for anyone who missed the post-incident refresher.