BAU (Business as Usual)

PCIComplianceHubLast updated

The Council's term for security that runs as part of normal operations rather than as an annual event before the assessment: controls monitored continuously, failures detected and responded to, changes assessed for their effect on scope and on the controls, and responsibilities assigned and understood.

Applies to. Every entity, and most sharply those that self-assess, because an SAQ answered once a year describes a day and PCI DSS describes a year.
Example. A firewall rule review happens every six months because 1.2.7 says so, the results are recorded, and the missed one in March is noticed in April by the person accountable for it, not by the assessor in November.
Limits. BAU is described in the standard's introductory section 5 as a best practice and is not itself a requirement, but several controls are its mechanics: 12.4.1 makes executive management responsible, 12.5.2 confirms scope at least annually and on significant change, 6.5.2 confirms controls after a significant change, and 10.7 detects, reports and responds to control failures. An entity that cannot show a control operating between assessments is not compliant on the days in between.
In PCI DSS v4.0.1. 12.4.1, 12.5.2, 6.5.2