Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

dual control and split knowledge — Dual Control and Split Knowledge: The Difference That Fails Audits

Dual Control and Split Knowledge: The Difference That Fails Audits

Dual control and split knowledge are two different controls that get treated as one, and the confusion between them is among the most reliable ways to fail a PCI PIN assessment. One is about who performs an operation. The other is about who can reach the material. Satisfying either on its own leaves a hole.

This guide sets out what each actually requires, the arrangements that look compliant and are not, and how to design them so that a failure is impossible rather than merely prohibited.

What this guide covers

dual control and split knowledge explained
Dual control governs who performs an operation; split knowledge governs who can reach the material.

What dual control and split knowledge each mean

Dual control is a process that needs two or more people, each doing something the other cannot do alone, such that no individual can complete it. The test is whether the process physically stops without both parties.

Split knowledge is a condition in which no single person holds — or can obtain — enough key material to reconstruct a key. The test is about access, not about who is currently holding what.

They are independent. You can have dual control without split knowledge: two people run a ceremony, but one of them could get hold of both components afterwards. You can have split knowledge without dual control: components are properly separated, but one administrator can start and finish a loading session alone.

The arrangement that fails most often

One person sits at the console and works. A second person stands behind them and watches. Everyone signs the form.

That is four-eyes review, and it is not dual control. The watcher contributes nothing the process depends on; remove them and the operation still completes. An assessor will say so, and the remedy is not a better form — it is a redesign in which the second party performs a step the first cannot.

The honest test is a single question asked of every step: what does the second person do that makes it impossible for the first to proceed alone? If the answer is “observes”, the design is wrong.

Split knowledge is about access, not possession

This is the half that quietly fails. A custodian who does not hold a second component but could obtain it has broken the requirement, whether or not they ever do.

Arrangement Why it breaks split knowledge
Two components in the same safe, in different envelopes Anyone who opens the safe has both
One custodian knows both combinations Possession is irrelevant; access is sufficient
Facilities holds a master key to both containers A third party can assemble the key
The safe supplier retains an override code As above, and it is usually undocumented
An administrator can read both components from a key-management system Logical access counts
The same person is named backup custodian for both components The backup appointment defeats the separation
Both components travel in the same courier consignment One interception yields the key

The question that finds these is not “who holds this component” but “who else could open that container”. Ask it about every container, and include line management, facilities, suppliers and anyone able to issue a replacement.

Where the PIN standard asks for dual control and split knowledge

Dual control and split knowledge are not one requirement. Control Objective 4, which covers key loading, carries several distinct obligations that are easy to collapse into a single policy paragraph and thereby leave partly unevidenced:

  • Loading from components uses dual control and split knowledge
  • Procedures prohibit any one person from accessing enough components to form a key
  • Loading clear-text keys with a key-loading device requires dual control to authorise the session, such that one person cannot enable it
  • Hardware and the passwords or codes used in loading are held in a secure environment under dual control
  • Physical tokens are not in the control or possession of any one individual who could use them alone
  • A person with access to any component, or to the media carrying it, has no access to others

Session authorisation is a separate obligation from component separation. A process where two custodians each enter a component, but either could have opened the session alone, satisfies one and fails the other.

Designing dual control and split knowledge that hold

Designing dual control and split knowledge starts on paper: write down, per operation, what each party does and why one alone cannot proceed. A table with a row per step and a column for each party is more useful than any amount of policy prose, because a cell that reads “observes” is visibly the problem.

Then do the same for the material. Per key, record the component, the custodian, the container, and — the column that finds problems — who else can obtain it. If that column is not empty, the separation is notional.

Spares are the usual route by which one person ends up with a complete set. Record spare tokens in the same register, store them apart from the ones they duplicate, hold them with a different individual, and require two authorisers to issue a replacement.

Dual control and split knowledge in a key ceremony

A generation ceremony is where both controls are exercised together, and where an assessor is most likely to ask to watch. Working through one shows how the two interlock.

Before it starts, the ceremony lead confirms the participants are appointed custodians holding no conflicting material — that is split knowledge, verified rather than assumed. The environment is checked, including whether any camera can see the keypad or printed output, because a camera that can read a component turns the whole ceremony into a recording of the key.

During it, each step names what party A does and what party B does. Components are entered one at a time, from a position where no other participant can observe, and each custodian steps away before the next entry. Nobody handles anyone else’s document or medium. That is dual control in operation rather than on paper.

Afterwards, each custodian seals their own component themselves, immediately, and the residue is destroyed and witnessed before the room is released. A component left in an output tray while someone fetches packaging has been exposed, and the timestamps on the record will show the gap.

Testing rather than inspecting

At review time, test dual control and split knowledge instead of reading the procedure. Attempt to enable a loading session with one credential set and confirm it is refused. Ask who can open each container without the custodian present. Review entitlements over any key-management system, not just named users. Check whether a leaver’s credentials were actually revoked.

A review that reads the procedure and ticks it has tested nothing. Where dual control and split knowledge are concerned, the finding you want to make is the one an attacker would have found.

What to do when separation has failed

Where dual control and split knowledge have failed, treat every key affected as compromised, whether or not anyone accessed the conflicting material. The requirement is breached by the possibility, not by the act, so waiting for evidence of misuse is not an option the standard leaves open.

That means replacing the key and its subsidiary and derived keys, destroying the old material, and recording the root cause — which is almost always a process gap rather than an individual’s error. A custodian who ended up with both components usually did so because a leaver was replaced without anyone re-verifying the separation.

Why the two controls exist separately

It is worth understanding the threat each answers, because that is what stops a programme collapsing them back together.

Dual control answers the insider who wants to do something — inject a key of their choosing, load a device that should not be loaded, run an operation outside the authorised window. Requiring two participants means acting alone is impossible, so the attack needs collusion.

Split knowledge answers the insider who wants to know something — the value of a key. Separating the material means no individual ever sees enough of it, so again the attack needs collusion. The standard states this directly for key generation: compromise of the process must not be possible without collusion between at least two trusted individuals.

Collapse the two and you close one door while leaving the other open, which is precisely the position an organisation is in when its ceremony has two participants and its safe has one master key.

Both controls are exercised hardest inside a key injection facility, and a Qualified PIN Assessor will usually ask to watch them operating rather than read about them.

Frequently asked questions

Is four-eyes review the same as dual control and split knowledge?

No. Four-eyes review has one person act and another observe. Dual control requires each party to perform something the other cannot, so the operation cannot complete with one person.

Can one person be a backup custodian for two components?

No. The backup appointment gives them access to both, which defeats split knowledge even if they never exercise it.

Does a two-person sign-off form evidence dual control?

Only if the process genuinely required two people. A signature from someone who watched evidences attendance, not control.

Where does the PIN standard set these out?

Mainly across Requirements 12, 13 and 14 in Control Objective 4, with related obligations in Control Objective 6. The standard is free to download from PCI SSC’s document library after accepting their licence.

Getting the documentation together

Evidencing dual control and split knowledge takes three artefacts: a matrix naming who does what in each operation and why one alone cannot proceed, a separation register recording who else can reach each container, and the per-session records that show both actually operated on the day.

Our PCI PIN Security Toolkit ships all three among its 149 templates, covering all 145 sub-requirements of the standard. See also our guides to the PCI PIN Security Requirements and to PCI PIN scope, which determines how many of those requirements apply to you.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.