The main purpose of the report is understanding regarding information security in the University of Melbourne. The most significant responsibilities of InfoSec involve formation of a set of few business procedures, which would secure the information asset, regardless of the procedure of formatting the information, whether it is in transit or not. Most of the larger enterprises eventually employ anyone dedicated security group for successful implementation as well as maintenance of organizational infuse programs. This type of security group is being controlled by the chief InfoSec officer within any particular organization. The programs of InfoSec are being built with the most distinctive purposes of CIA triad that are confidentiality, integrity and availability of the systems of information technology or even business data. Various risks to information security with suitable suggestions are provided in this report for the University of Melbourne.