This essay provides an in-depth analysis of Information System (IS) security and risk management at Altium Limited, an Australian software company specializing in PC-based electronics design software. It begins by outlining Altium's services and how information systems support its business operations, particularly in marketing, sales, production, accounting, and finance. The essay then discusses General Management Controls (GMCs) implemented by Altium, focusing on law and compliance, integrity and competence, and safeguards. It further explores Application Controls (ACs) such as completeness checks, validity checks, identification, authentication, authorization, input control, and forensic control. A comparison of ACs and GMCs highlights their roles in securing the information system and managing organizational resources. The essay evaluates risk management techniques for reliability, confidentiality, availability, integrity, and security, including loss prevention and risk avoidance, as well as techniques for risk identification, assessment, and control, such as separation and loss reduction. Finally, it details Altium's audit plan and process, covering audit requirement identification, report requirement noting, conflict of interest assessments, risk assessment, document and record assessment, discussion of scope and objectives, procedural information collection, evaluation of various controls and plan execution.