You're an independent consultant engaged to give Tessera assurance over its Essential Eight posture, after this year's incident. This is the kickoff. Before you scope anything, go and understand the business — read Tessera's policy library and Statement of Applicability, and meet the people. Nobody will tell you where the gaps are; an auditor works that out.
"After TSR-INC-2025-031, the board wants independent confirmation that our Essential Eight controls are real, not just written down. Our Statement of Applicability says we're in good shape. I'd rather you tested that than took it from me. Focus where it matters — you won't be able to cover everything, and you won't get onto our endpoints."
An advisory / self-audit — Tessera hired you to find and fix gaps; the motive for an honest result is reputation and improvement, not a certificate. Different from ISO 27001 certification (a formal, accredited, third-party audit with a defined scope and surveillance audits). Don't conflate them.
Choose the Essential Eight controls to assess. You can't cover everything — deciding what matters most for this company, post-incident, is your call. The endpoint controls (marked) can only be partly tested: you have policies and people, but no access to Tessera's endpoints, so you can't verify enforcement — you'd rate what you can and record the limitation.
No controls scoped — go back to Scope.
Scope and do some fieldwork first.
Generate the report to assemble findings, evidence, recommendations and appendices.