My company is in the middle of a PCI (Payment Card Industry) audit, and the auditors are asking for some documentation (from Microsoft) on how, at a technical level, RMS 1.3 handles credit card information. I can't find a white paper or anything on the topic, just one blurb in a press release that says "Security for credit card information is based on the PCI Payment Application Best Practices."
Does anyone know if such documentation exists?