ST1119
The organization ensures that, upon learning of a confirmed negative testing result or audit finding pertaining to its SCP, it will take immediate and effective action, to the extent possible, to identify and implement compensating controls until the root cause of the weakness can be determined and…
Plain-language summary
What it actually means.
Plain-language summary forthcoming. Source text below.
Source text
As written.
The organization ensures that, upon learning of a confirmed negative testing result or audit finding pertaining to its SCP, it will take immediate and effective action, to the extent possible, to identify and implement compensating controls until the root cause of the weakness can be determined and remediated.
Assessed by HEXDI
What HEXDI assesses.
- M11
1 — AUDITS AND ASSESSMENTS
Program has procedures for investigating the underlying root causes giving rise to program deficiencies and other internal control problems…
- M11
7 — AUDITS AND ASSESSMENTS
Program has procedures for developing, tracking and ensuring timely completion of corrective actions within established time frames.
Related
Other DOT standards.
Source & revisions
- First mapped
- Jun 8, 2022
- Last updated
- May 26, 2026 (30m ago)
- Source
- Framework for OFAC Compliance Commitments