This section of Protiviti's "Guide to The Sarbanes-Oxley Act" addresses common questions concerning identifying, documenting and assessing internal controls. Some topics covered are: How and why are entity-level controls assessed? How are IT risks and controls considered? Do SAS 70 reports apply to processes other than IT and to specialists? And, what are walkthroughs, why are they necessary and how should the Section 404 compliance team prepare for them?