This section of Protiviti's “Guide to the Sarbanes-Oxley Act: IT Risks and Controls – Frequently Asked Questions" addresses activity and process-level considerations for application-level controls. Topics covered include: What are the application-level control considerations? How does the Section 404 compliance project team determine the critical applications for each key business process? And, how does the Section 404 compliance project team integrate the consideration of application level controls with business-process controls at the activity/process level?