This report provides a detailed analysis of IS security and risk management practices within the Royal Melbourne Hospital. It begins with an executive summary and introduction, setting the stage for a comprehensive examination of network device vulnerabilities, specifically focusing on routers and switches, and the associated threats they face. The report then explores various network security devices, such as firewalls and uninterruptible power supplies, and how they can be implemented to control security. Furthermore, it delves into ensuring web service availability using Windows Server 2016, the impact of employees on information security, and the application of Windows Server 2016 auditing tools. The second part of the report addresses encryption. The report concludes with a summary and cited works.