I was given your name as Symantec’s contact for obtaining information related to our annual supplier due diligence process. Following are the items we need for this purpose:
• Completed SIG Lite spreadsheet (attached to this email). Please fill out both the Business Information and Lite tabs.
• SOC 2 Type II or ISO 27001 Certificate. If you don’t have either please let me know so we can discuss other options.
• Business Continuity Plan - summary of the plan is fine
• Disaster Recovery Test Results – summary of the test results is acceptable
• Information Security Policy
• Penetration and vulnerability testing methodology - provide reports of all testing completed that show how Symantec applicable endpoints / websites are tested, i.e., executive summary of pen test results, final vulnerability scan report showing that all critical web vulnerabilities are remediated for any hosted Internet accessible sites.
If you are not the correct person, please forward to the appropriate staff. I am available to answer any questions via email or phone, or to go over any of the requested items for clarification.