Skip to content

Dual Control

What is Dual Control?

A security procedure requiring two authorized individuals to perform a critical action simultaneously, preventing any single person from acting alone.

Information Security

What the standards actually require on dual control

Requirements naming dual control across 4 standards, quoted from the control text.

Keys must be loaded into POI devices and HSMs in a secure manner that prevents disclosure or substitution, with appropriate dual control, witness verification, and detailed logging.

CO-7 · Key Loading Is Handled in a Secure Manner
PCI P2PE2 controls

Cryptographic keys used to protect account data must be generated using methods that ensure unpredictability, sufficient strength, and proper documentation under dual control and split knowledge.

Domain-5.1 · Key Generation
ISMAP (Japan)1 control

ISMAP Cloud Governance establishes the management framework for Cloud Service Providers operating under ISMAP. (1) Information Security Management System (ISMS): based on ISO/IEC 27001:2022 + JIS Q 27001 (Japanese Industrial Standard equivalent) + ISMS-AC Info...

ISMAP-CloudGovernance-ISMS-RiskAssessment-SharedResponsibility-Policy-RegulatoryCompliance-RolesResponsibilities · ISMAP Cloud Governance - ISMS per ISO 27001/JIS Q 27001 + Risk Assessment + Shared Responsibility Model + Cloud Security Policy + Regulatory Compliance + Roles and Responsibilities
PCI DSS 4.01 control

Where manual cleartext key management operations are performed, they use split knowledge and dual control.

3.7.6 · Manual cleartext key operations use split knowledge

Questions people ask about dual control

What is Dual Control?
A security procedure requiring two authorized individuals to perform a critical action simultaneously, preventing any single person from acting alone.
Why is Dual Control important for compliance?
Dual Control is a key concept in Information Security. Understanding dual control helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Dual Control?
Dual Control appears in the requirement text of PCI PIN Security, PCI P2PE, ISMAP (Japan), PCI DSS 4.0. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Dual Control?
Explore our compliance framework pages to see how dual control applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Dual Control applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.