Audit Workbench Tessera · Essential Eight

Planning meeting — the Tessera engagement

You're an independent consultant engaged to give Tessera assurance over its Essential Eight posture, after this year's incident. This is the kickoff. Before you scope anything, go and understand the business — read Tessera's policy library and Statement of Applicability, and meet the people. Nobody will tell you where the gaps are; an auditor works that out.

From: Isabella Ferreira, CISO — engagement brief

"After TSR-INC-2025-031, the board wants independent confirmation that our Essential Eight controls are real, not just written down. Our Statement of Applicability says we're in good shape. I'd rather you tested that than took it from me. Focus where it matters — you won't be able to cover everything, and you won't get onto our endpoints."

🏢 Go look first. Open Tessera in another tab — the policies, the Statement of Applicability, and the staff you can interview — and form your own view of where the risk is.

What kind of audit is this?

An advisory / self-audit — Tessera hired you to find and fix gaps; the motive for an honest result is reputation and improvement, not a certificate. Different from ISO 27001 certification (a formal, accredited, third-party audit with a defined scope and surveillance audits). Don't conflate them.

📸 An audit is a snapshot. Your findings describe the controls at the time you tested them — not a warranty they still hold next week.

Interview tips — inquiry is evidence if you do it well

  • Work out who's relevant yourself — Tessera has a dozen staff; most aren't relevant to a given control.
  • Ask for evidence, not assurance: "show me the last restore test" beats "do you test backups?"
  • Corroborate. One person's claim is a lead, not a finding — confirm it against a document or a log.
  • Follow the exceptions. "For everyone?" and "since when?" surface the gap between policy and practice.
⚖️ How you're assessed: not on the verdict — there's no single right answer — but on whether you substantiated it: relevant evidence, corroborated, defensible. A Partial you can defend beats a Met you can't.

Scope — what will you audit, and why?

Choose the Essential Eight controls to assess. You can't cover everything — deciding what matters most for this company, post-incident, is your call. The endpoint controls (marked) can only be partly tested: you have policies and people, but no access to Tessera's endpoints, so you can't verify enforcement — you'd rate what you can and record the limitation.

🗄️ Evidence room — everything available to you

These link into Tessera. The tool won't tell you which bear on a control — working that out is the audit.

Fieldwork

No controls scoped — go back to Scope.

Review

Scope and do some fieldwork first.

Generate the report to assemble findings, evidence, recommendations and appendices.