This section of Protiviti's “Guide to the Sarbanes-Oxley Act: IT Risks and Controls – Frequently Asked Questions" focuses on testing, addressing deficiencies and reporting. Topics covered include: How are IT controls tested? How should management address deficiencies and gaps in IT controls? And, how will the external auditor view IT controls during the attestation process?