Abstrak - Sistem informasi saat ini mengambil peran penting dalam banyak organisasi, termasuk Universitas. Salah satu penerapan sistem informasi pada universitas adalah Portal Akademik. Website Portal Akademik Universitas Malikussaleh memberikan akses kepada mahasiswa, dosen, dan pegawai untuk mendapatkan layanan yang dibutuhkan. Namun risiko keamanan pada Portal Akademik juga sangat besar. Dalam penelitian ini digunakan metode OWASP ZAP untuk mengkaji keamanan website Portal Akademik Universitas Malikussaleh. Dari hasil pengujian yang telah dilakukan didapatkan 7 kerentanan yang mencakup, 3 kerentanan level medium, 2 kerentanan level low, dan 2 kerentanan bersifat information. Adapun rating skor yang didapatkan untuk likelihood adalah sebesar 5,69 dan impact levels sebesar 4,81. Hal ini menunjukan bahwa website Portal Akademik Universitas Malikussaleh memiliki tingkat risiko medium, yang berarti masih diperlukan perbaikan terhadap kerentanan yang muncul untuk memastikan website tetap aman dari sejumlah serangan.Kata kunci: Keamanan Sistem Informasi, OWASP ZAP, Website, Portal Akademik, OWASP Risk Rating Abstract - Information systems currently play a crucial role in many organizations, including universities. One application of information systems in universities is the Academic Portal. The Academic Portal website of Malikussaleh University provides access for students, lecturers, and staff to obtain the services they need. However, the security risks associated with the portal are also significant. In this study, the OWASP ZAP method was used to assess the security of the Academic Portal. From the assessment, several vulnerabilities from the carried out testing were identified. These vulnerabilities including seven advanced level vulnerabilities, three medium-level vulnerabilities, two low-level vulnerabilities, and two informational vulnerabilities. As for the ratings obtained for likelihood were 5.69, and 4.81 for impact levels. This indicates that Malikussaleh University Academic Portal has a medium risk level, meaning that improvements are still needed to address the identified vulnerabilities and ensure the website remains secured against various attacks.Keywords: Information System Security, OWASP ZAP, Website, Academic Portal, OWASP Risk Rating
Copyrights © 2024