August 15, 2007
Jim Scott
President
Records Management Solutions, Inc.
Via email: jims@rmsstorage.com
Dear Mr. Scott:
Re: Acceptance of Visa CISP Level 3 Compliance Validation for Records Management Solutions, Inc.
Visa USA is pleased to accept Records Management Solutions, Inc.’s PCI Self-Assessment Questionnaire and Network Perimeter Scan results. Visa recognizes that this questionnaire is based on Records Management Solutions, Inc.’s assessment and opinion.
Thank you for your participation in the Visa USA Cardholder Information Security Program (CISP), and for your diligence in operating within the compliance standards of Visa CISP. Although security can never be completely guaranteed, your efforts to adhere to CISP data security requirements should reduce the ability of hackers to gain access to proprietary data.
This letter and your company’s inclusion on Visa’s List of Compliant Service Providers evidence Visa’s acceptance of the Records Management Solutions, Inc. PCI Self-Assessment Questionnaire and Network Perimeter Scan results. The List of Compliant Service Providers, located at (www.visa.com/cisp), acknowledges those service providers that have shown their commitment to security by meeting the rigorous requirements of Visa CISP.
Please note that Visa CISP requires annual revalidation. If Visa has not received Records Management Solutions, Inc.’s updated PCI Self-Assessment Questionnaire and summary of each quarterly network perimeter scan by your revalidation due date of 6/30/2008, Visa will remove your company from the List of CISP Compliant Service Providers.
Visa may revoke this Acceptance and remove Records Management Solutions, Inc. from the List of CISP Compliant Service Providers at any time that Visa, in its sole discretion, determines that your company is not adhering to Visa CISP requirements or that Records Management Solutions, Inc.’s PCI Self-Assessment Questionnaire and Network Perimeter Scan results were inaccurate.
We see tremendous value in Records Management Solutions, Inc.’s participation in this crucial security program. We appreciate your continued support and commitment to safeguarding the payment industry.
Sincerely,
Eduardo Perez
Vice President, Payment System Risk & Compliance