Claim Missing Document
Check
Articles

Found 1 Documents
Search
Journal : Journal of Information Systems and Informatics

Security Analysis of Indonesian Region Government Web Applications Based on NIST SP 800-115 and WSTG v4.2 Arizal; Muhammad Hilal; Dimas Febriyan Priambodo
Journal of Information System and Informatics Vol 8 No 2 (2026): April
Publisher : Asosiasi Doktor Sistem Informasi Indonesia

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.63158/journalisi.v8i2.1558

Abstract

The rapid adoption of e-government systems has increased the exposure of government web applications to cybersecurity threats with the lack of security-focused implementation. Previous studies on web application security assessment commonly using automated vulnerability scanners or validated with another tools, which may produce false positives and fail to provide comprehensive insights. This research addresses this limitation by conducting a structured and multi-target security assessment of regional government web applications. The assessment integrates a systematic penetration testing process with comprehensive web application security testing guidelines. Automated scanning using OWASP ZAP and Arachni was combined with manual validation to ensure the accuracy of findings. The results identified nine validated vulnerabilities in the government portal and public service applications, and ten vulnerabilities in the legal documentation system. A significant portion of initial findings were confirmed as false positives after manual verification, highlighting the limitations of automated tools. The most common vulnerabilities were related to security misconfigurations, including missing security headers, outdated JavaScript libraries, and insecure cookie settings that highlight on weak in configuration hygiene and dependency management in this regional goverment. This study also demonstrates that combining structured penetration testing with detailed validation provides a more accurate and reliable assessment of government web application security.
Co-Authors Abdul Abror Achmad, Fahdel Adiati, Nadia Paramita Retno Aditama, Whisnu Yudha Afif, Yusrizal Agus Reza Aristiadi Nurwa Ahmad Ashari Ajhari, Abdul Azzam Akhmad Rizal, Akhmad Amiruddin Amiruddin Amiruddin Amiruddin Amiruddin Annisa Nurul Puteri ARIZAL Arya, Primadona Asep Dadan Rifansyah Awalin, Lilik Jamilatul Azzahra, Arsya Dyani Beatrix, Yehezikha Briliyant, Obrina Candra Dhana Arvina Alwan Diaz Samsun Alif Dozy Arti Insani Fachrurozy, Rizky Fadlilah Izzatus Sabila Faizi, Achmad Husein Noor Farida, Yeni Furqan Zakiyabarsi Ghiffari Adhe Permana Girinoto Gusti Agung Ngurah Gde K.T. D Hafidz Faqih Aldi Kusuma Handayani, Annisa Dini Henny Yulianti Hermawan Setiawan I Komang Setia Buana, I Komang Indarjani, Santi Ira Rosianal Hikmah Jayanti Yusmah Sari Jeckson Sidabutar La Ode Ahmad Saktianyah La Ode Hasnuddin S. Sagala Lestari, Andriani Adi Mahar Surya Malacca Muhammad Hasbi Muhammad Hasbi Muhammad Hilal Muhammad Yusuf Bambang Setiadji Muhammad Yusuf Bambang Setiadji Mukhamad Najib Nanang Trianto Nanang Trianto Naufal Hafiz Nirsal Nirsal Noorhasanah Zainuddin Nurwa, Agus Reza Aristiadi Obrina Candra Briliyant Olga Geby Nabila Pandi Vigneshwaran Pandi Vigneshwaran Prasetyo, Arbain Nur Prayoga, Arga Prisma Megantoro Rabiah Adawiyah Rahmat Purwoko Rahmawati, Fika Dwi Rizki Putra Prastio Rizky Fachrurozy Sabela Trisiana Oktavia Saptomo, Wawan Laksito Yuly Siswantyo, Sepha Sri Siswanti Suci Pricilia Lestari Suharsono Bantun Sunaringtyas, Septia Ulfa Syaban, Kharis Syahrul Syahrul Tiyas Yulita Wahyu Riski Aulia Putra Windarta, Susila Yulandi Yusuf Bambang Setiadji