Claim Missing Document
Check
Articles

Found 1 Documents
Search

Network Infrastructure Security Audit at a Vocational School Teaching Factory Using the NIST Cybersecurity Framework Maya Destriani; Bintang Najarul Haq Mulyadi; Tazkia Salsabila Ardan
INTENSIF: Jurnal Ilmiah Penelitian dan Penerapan Teknologi Sistem Informasi Vol 10 No 2 (2026)
Publisher : Universitas Nusantara PGRI Kediri

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.29407/intensif.v10i2.28354

Abstract

Background: The increasing dependence on public-facing network services exposes educational institutions to growing cybersecurity threats, highlighting the need for structured security evaluations. This study evaluates cybersecurity maturity in a vocational school Teaching Factory (TEFA) environment using the NIST Cybersecurity Framework (NIST CSF) 1.1. Objective: To assess the cybersecurity maturity of the network infrastructure at TEFA TKJ SMK Al-Mufti, determine its implementation tier, and develop practical security improvements. Methods: A qualitative–quantitative descriptive case study was conducted using observations, interviews, questionnaires based on NIST CSF categories and subcategories, and document analysis. Risk assessment followed NIST SP 800-30, while gap analysis compared the Current Profile with a Target Profile defined at Tier 3 across the five NIST CSF core functions. Results: Although questionnaire results produced an average score of 3.45 (Tier 3), qualitative validation indicated that cybersecurity practices remained informal and inconsistently documented, resulting in an actual maturity level of Tier 2 (Risk Informed). A one-level gap was identified across all NIST CSF functions. Key risks included weak authentication, the absence of formal cybersecurity policies, and manual log monitoring. Implementing centralized log monitoring using Graylog improved visibility and strengthened the Detect and Respond functions. Conclusion: NIST CSF effectively identifies cybersecurity gaps and supports targeted improvements in educational network infrastructures. Further research should evaluate the long-term effectiveness of implemented controls and extend assessments to multiple institutions.