This section of Protiviti's "Guide to the Sarbanes-Oxley Act: Managing Application Risks and Controls – Frequently Asked Questions" addresses common questions about general application risk and control considerations for complying with Sarbanes-Oxley. Topics covered include: What does Section 404 say about an organization’s reliance on critical business applications? What is a public company required to disclose regarding an ERP/application implementation? And, what are the typical application control types as they relate to Section 404 compliance?