MONA RATULIU
Program Studi Keamanan Sistem Informasi, Politeknik Negeri Bengkalis

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

PERANCANGAN SISTEM INFORMASI WEBSITE DESA UNTUK PELAYANAN SURAT-MENYURAT DENGAN PENDEKATAN SECURE SOFTWARE DEVELOPMENT LIFE CYCLE (SSDLC) MONA RATULIU; Nurmi Hidayasari
Rabit : Jurnal Teknologi dan Sistem Informasi Univrab Vol 11 No 1 (2026): Januari
Publisher : LPPM Universitas Abdurrab

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.36341/rabit.v11i1.7589

Abstract

Correspondence administration services are one of the primary services provided by village governments to the community. However, in Teluk Lancar Village, the correspondence service process is still carried out manually, resulting in various issues such as service delays, data recording errors, and potential security risks to community data. In addition, the manual system makes it difficult for the community to monitor the status of submitted correspondence requests. This study aims to design and implement a village website information system for correspondence services by applying the Secure Software Development Life Cycle (SSDLC) approach with a focus on improving system security. The implementation of SSDLC in this study focuses on three main stages, namely Secure Design, Secure Coding, and Security Testing. In the Secure Design stage, the system is designed by implementing Role-Based Access Control (RBAC) to restrict user access based on the roles of community members, operators, and village administrators. The Secure Coding stage is implemented through role-based access control, input validation, and page access protection to prevent unauthorized access. Furthermore, the Security Testing stage is conducted using OWASP ZAP to identify potential security vulnerabilities in the system. The results show that the RBAC mechanism has been successfully implemented and is able to restrict user access according to their roles. Security testing results indicate the presence of vulnerabilities categorized as High, Medium, Low, and Informational, with the majority classified as low risk. The identified high-risk finding is related to application security misconfiguration (missing security headers), which does not directly affect data confidentiality but serves as an important basis for security evaluation and remediation in subsequent development stages.