This section of Protiviti's “Guide to the Sarbanes-Oxley Act: IT Risks and Controls – Frequently Asked Questions" addresses activity and process-level considerations for application and data-owner processes. Topics covered include: Who are the application and data owners? What are the role and responsibilities of the application and data owners in relation to the IT organization? And, what process should the application and data owners have in place to facilitate compliance with Sections 404 and 302?