Dual Control
What is Dual Control?
A security procedure requiring two authorized individuals to perform a critical action simultaneously, preventing any single person from acting alone.
Frameworks that govern dual control
What the standards actually require on dual control
Requirements naming dual control across 4 standards, quoted from the control text.
Keys must be loaded into POI devices and HSMs in a secure manner that prevents disclosure or substitution, with appropriate dual control, witness verification, and detailed logging.
CO-7 · Key Loading Is Handled in a Secure Manner →Cryptographic keys used to protect account data must be generated using methods that ensure unpredictability, sufficient strength, and proper documentation under dual control and split knowledge.
Domain-5.1 · Key Generation →ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Info...
ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities · ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities →Where manual cleartext key management operations are performed, they use split knowledge and dual control.
3.7.6 · Manual cleartext key operations use split knowledge →Questions people ask about dual control
What is Dual Control?
Why is Dual Control important for compliance?
Which compliance frameworks address Dual Control?
Where can I learn more about Dual Control?
See how Dual Control applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.