Jurnal Teknologi Sistem Informasi dan Aplikasi
Vol. 7 No. 3 (2024): Jurnal Teknologi Sistem Informasi dan Aplikasi

NIST Cyber Security Framework Development for Website Information Collection

Nugroho, Firdan Rafi (Unknown)
Afiana, Fiby Nur (Unknown)
Kuncoro, Adam Prayogo (Unknown)



Article Info

Publish Date
31 Jul 2024

Abstract

The rapid development of websites has made them one of the most important modern information media. However, this growth has also highlighted the critical need for robust website security to protect the data and information they contain. The website dobelhost.com was analyzed for security vulnerabilities, revealing several issues, including the absence of the X-Frame-Options header, the lack of an HTTP Strict Transport Security (HSTS) policy, the disclosure of server information through the X-Powered-By header, the absence of a Content Security Policy (CSP) to guard against XSS attacks, and the presence of mixed content. To address these vulnerabilities, the study employed a comprehensive method involving information gathering, implementing security headers, updating software and plugins, and enforcing HTTPS. The results demonstrated significant improvement, effectively resolving the identified vulnerabilities. This research provides a useful reference for the development or enhancement of similar websites, increasing awareness and vigilance against potential threats, and achieving better cyber resilience. The research has been completed successfully, demonstrating the effectiveness of the proposed method in resolving the identified security issues.

Copyrights © 2024






Journal Info

Abbrev

JTSI

Publisher

Subject

Computer Science & IT

Description

Jurnal Teknologi Sistem Informasi dan Aplikasi is a publication media of scientific paper in the field of technology and information systems which can be in the form of analysis, development, and application, but not limited to it. Topics cover the following areas (but are not limited to) Business ...