Gabriel Indra Widi Tamtama
Institute of Service Science, College of Technology Management, National Tsing Hua University, Hsinchu City, Taiwan

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Integrating the NIST 800-30 Risk Management Framework with Penetration Testing: A Case Study of Web-Based Training Information Systems in a Cybersecurity Company Yohanes Dewantara Marpaung; Halim Budi Santoso; Erick Kurniawan; Gabriel Indra Widi Tamtama; Abdul Karim
Indonesian Journal of Information Systems Vol. 9 No. 1 (2026): August 2026
Publisher : Program Studi Sistem Informasi Universitas Atma Jaya Yogyakarta

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.24002/ijis.v9i1.14877

Abstract

Web application security has become a paramount concern due to the escalating frequency of cyber threats targeting internet-based information systems. Web developers must prioritize risk management, with a particular emphasis on integrating risk identification within the information security management system. Companies specializing in information security management must exercise caution when deploying web-based applications, as information security is a critical issue that can substantially affect a company's reputation. However, previous research has frequently failed to address this issue comprehensively. Consequently, this study seeks to investigate the integration of a risk management framework with penetration testing. The amalgamation of penetration testing with NIST SP 800-30 is expected to provide a comprehensive risk assessment. The penetration testing was conducted using a grey-box testing methodology, guided by OWASP WSTG v4.2 and augmented by CVSS v3.1 for severity measurement. Subsequently, NIST SP 800-30 was employed as the risk management framework. The grey-box testing was performed on a recently deployed web-based training management system. As a result, four vulnerabilities were identified and verified through Proof of Concept: SQL Injection (High), Blind Stores XSS (Critical), Unrestricted file upload enabling remote code execution (Critical), and Brute Force Attack (High). A comprehensive risk identification and mitigation process was then conducted for these vulnerabilities. This study also provides improvement suggestions to aid in mitigating the identified vulnerabilities. This research introduces a novel approach by integrating penetration testing with risk management frameworks to enhance the effectiveness of risk management in web-based applications