Claim Missing Document
Check
Articles

Found 5 Documents
Search

Manajemen Risiko Serangan Siber Menggunakan Framework NIST Cybersecurity Tony Tan; Benfano Soewito
JISAMAR (Journal of Information System, Applied, Management, Accounting and Research) Vol 6 No 2 (2022): JISAMAR: May 2022
Publisher : Sekolah Tinggi Manajemen Informatika dan Komputer Jayakarta

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.52362/jisamar.v6i2.781

Abstract

Pendidikan tinggi pada saat ini telah menggunakan sistem teknologi informasi seperti sistem layanan berbasis web dan situs web sebagai sarana untuk mendukung pelaksanaan pendidikan. Oleh karena itu, sistem teknologi informasi yang terdapat pada kampus harus terjaga keamanan dan ketahanannya guna untuk memberikan pelayanan yang terbaik untuk dosen, staf, dan mahasiswa. Tidak menutup kemungkinan, sistem teknologi informasi yang terdapat pada kampus memiliki cela peretasan yang bisa dimasuki oleh penjahat dunia maya atau hacker. Oleh karena itu, perlu adanya metode untuk meningkatkan keamanannya. Dalam studi ini, kami menguji keamanan siber pada Universitas ZXC dengan menggunakan Framework NIST Cybersecurity. Pengambilan data dilakukan dengan cara wawancara, studi dokumentasi insiden, dan observasi. Penilaian terhadap 39 sistem layanan web dan situs web. Penulis juga menggunakan aplikasi Nessus untuk menilai cela dan tingkat ancaman. Hasil dari penilaian menunjukan hasil kondisi keamanan siber di lingkungan Universitas ZXC masih belum mencapai standar yang direkomendasikan. Hal serupa juga ditunjukan melalui hasil penilaian aplikasi Nessus yang menunjukan kondisi cela pada sistem layanan web dan situs web yang cukup banyak. Dari hasil penelitian ini, kami memberikan rekomendasi control menggunakan Framework NIST Cybersecurity untuk meningkatkan keamanan siber pada sistem layanan web dan situs web.
Analisis Keamanan Infrastruktur Jaringan Berdasarkan Cyber Kill Chain Framework Utama Hasiolan Panggabean; Benfano Soewito
JUSIFO : Jurnal Sistem Informasi Vol 9 No 1 (2023): June
Publisher : Program Studi Sistem Informasi, Fakultas Sains dan Teknologi, Universitas Islam Negeri Raden Fatah Palembang

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.19109/jusifo.v9i1.17365

Abstract

This study concentrates on examining the security of network infrastructure using the cyber kill chain framework approach. The research is conducted within a company operating in network security services. In its operations, it offers a Virtual Private Cloud (VPC) containing various crucial information such as applications, internal data, client data, and product demos. Despite the attractive features of cloud computing, there are significant threats as well. Handling attacks cannot be swiftly and efficiently executed, resulting in temporary operational unavailability until the attacks are resolved. This research delves into the security of the company's infrastructure by testing several points of vulnerability exploited by malicious parties. The cyber kill chain framework approach is employed to systematically assess the company's infrastructure. The study reveals that certain issues have been adequately detected; however, security gaps persist, as evidenced by the testing conducted and the inadequate response from the company's security systems.
Security Assessment Based on OWASP Top 10 Using SonarQube and ZAP on Export and Import Applications in the LNSW Muhammad Wisnu; Benfano Soewito
INTENSIF: Jurnal Ilmiah Penelitian dan Penerapan Teknologi Sistem Informasi Vol 10 No 1 (2026)
Publisher : Universitas Nusantara PGRI Kediri

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.29407/intensif.v10i1.25294

Abstract

Background: The advancement of information and electronic systems has significantly transformed export and import processes. In Indonesia, the Lembaga National Single Window (LNSW) plays a pivotal role in facilitating international trade by integrating procedures and information related to exports, imports, and document flows. Objective: This study aims to assess the security of LNSW’s export and import application by identifying vulnerabilities based on the Open Web Application Security Project (OWASP) Top 10 framework. It also compares the effectiveness of Static Application Security Testing (SAST) using SonarQube and Dynamic Application Security Testing (DAST) using ZAP (Zed Attack Proxy) in detecting various types of vulnerabilities. Methods: The analysis involved the use of SonarQube for source code scanning and ZAP for runtime testing. Each detected vulnerability was evaluated using the Common Vulnerability Scoring System (CVSS) to determine its severity level. Recommended mitigation strategies were provided accordingly. Results: A total of eight vulnerabilities were identified, comprising two High-severity and six Medium-severity issues. SonarQube proved more effective in detecting Identification and Authentication Failures (three instances), while ZAP excelled in identifying Vulnerable and Outdated Components (two instances). Notably, each tool uncovered four unique types of vulnerabilities that the other did not detect. Conclusion: These findings highlight the practical benefits of combining SAST and DAST techniques. By integrating both approaches, organizations can achieve a more comprehensive and reliable security assessment, ultimately leading to more resilient software systems. 
Integrated Healthcare IT Risk Management in a Hospital Setting: A Case Study of ISO 31000 and NIST SP 800-30 Implementation at Murni Teguh Tuban Bali Hospital Leo Denny Hartanto; Benfano Soewito
Equivalent: Jurnal Ilmiah Sosial Teknik Vol. 8 No. 3 (2026): Equivalent: Jurnal Ilmiah Sosial Teknik
Publisher : Politeknik Siber Cerdika Internasional

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59261/jequi.v8i3.387

Abstract

Background: Digital transformation in the healthcare sector has significantly increased the use of systems such as Hospital Information Systems (HIS), Electronic Medical Records (EMR), and technology infrastructure. This reliance increases risks of operational disruptions, cyber threats, and data breaches. Objective: This study aims to develop an integrated IT risk management framework that combines ISO 31000 and NIST SP 800-30, and to examine how this integration supports regulatory compliance and hospital accreditation requirements. Methods: A case study was carried out at Murni Teguh Tuban Hospital in Bali, Indonesia. Data were collected through interviews with seven informants from management and the IT unit, questionnaires, and direct observations. Risks were scored using a likelihood × impact matrix validated through source triangulation. Results: ISO 31000 was applied as the governance framework while NIST SP 800-30 guided the technical assessment at every stage. The results show that three key assets are categorized as having very high-risk levels, namely systems (20), external services and vendors (16), and hardware (15). In terms of threats, operational risks are the most significant (20). The evaluation also highlights several gaps, including the absence of Multi-Factor Authentication (MFA), lack of regular IT audits, and insufficient security monitoring. To address these issues, mitigation strategies focus on strengthening access controls, performing regular updates, and implementing a Disaster Recovery Plan (DRP). Conclusion: The combining of ISO 31000 and NIST SP 800-30 offers a more balanced approach, helping improve security, system resilience, and service continuity.
Construction of Early Notification Framework to Anticipate Clone Phishing using GoPhish and Wazuh to Increase Blue Team's Detection Speed Jeremy Pierre Tumbio; Benfano Soewito
Equivalent: Jurnal Ilmiah Sosial Teknik Vol. 8 No. 4 (2026): Equivalent: Jurnal Ilmiah Sosial Teknik
Publisher : Politeknik Siber Cerdika Internasional

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.59261/jequi.v8i4.408

Abstract

Background: Clone phishing can exploit trusted message formats and user behavior, while delayed event ingestion into a SIEM can prolong the interval during which a Blue Team remains unaware of a credential-compromise attempt. This study addresses the operational gap between phishing simulation events and automated security monitoring. Objective: This study develops and evaluates an early-notification framework that integrates Gophish, Wazuh SIEM, API-based event forwarding, and Telegram notifications, with the measurable objective of reducing phishing-event detection latency relative to manual event injection. Methods: A controlled comparative experiment was conducted in a Docker-based simulation environment using Gophish, MailHog, a Python API-polling engine, Wazuh SIEM, a Python integrator, and a Telegram bot. Manual Injection served as the baseline, while API Polling Forwarding served as the proposed mechanism. Detection latency was operationalized as the interval from the Gophish click timestamp to the Wazuh detection timestamp; Telegram delivery occurred after detection and was therefore not included in the mean time to detection (MTTD). Results: The aggregate comparison reported in the experiment showed an average detection latency of 72.60 seconds for Manual Injection and 3.73 seconds for API Polling Forwarding, corresponding to a 94.86% reduction in mean detection latency and a mean-detection-latency ratio of 19.46. These figures describe detection latency, not notification-delivery latency. Conclusion: Automated API-based forwarding substantially reduced the observed detection latency between Gophish and Wazuh and enabled automated post-detection notification to the Blue Team. Because polling introduces an interval-dependent delay, the framework is appropriately characterized as near-real-time rather than real-time.