Jurnal Pengembangan Sains dan Teknologi
Vol. 1 No. 2 (2025): Juli 2025

Security Analysis of XYZ Academic Information System Using Information System Security Assessment Framework (ISSAF)

Muhammad Amirul Mu'min (Unknown)
Yana Safitri (Unknown)
Sabarudin Saputra (Unknown)



Article Info

Publish Date
02 Apr 2025

Abstract

Academic information system security is a crucial aspect in the development of technology and information today, especially in maintaining structured and comprehensive data from various threats. Academic Information System (AIS) XYZ which provides services based on HTTP or HTTPS protocols is vulnerable to hacker attacks through security holes that may not be realized by the website owner. This study aims to identify and analyze security vulnerabilities in the AIS and provide recommendations for improvements to improve the level of system security. Using the ISSAF method to evaluate system security. The tools used in the analysis include Whois, SSL Scan, Nmap, OWASP Zap, and LOIC to detect and test vulnerabilities on the website. From this study, 12 vulnerabilities were found, consisting of four medium level vulnerabilities, six in moderate vulnerabilities, and two information level vulnerabilities. In improving system security, it is recommended to make improvements to the vulnerabilities found, especially at high and medium levels, and to implement regular security monitoring to prevent future attacks.

Copyrights © 2025






Journal Info

Abbrev

jrst

Publisher

Subject

Automotive Engineering Biochemistry, Genetics & Molecular Biology Chemical Engineering, Chemistry & Bioengineering Civil Engineering, Building, Construction & Architecture Computer Science & IT

Description

Fokus Jurnal Pengembangan Sains dan Teknologi bertujuan untuk menjadi platform untuk menerbitkan penelitian berkualitas di bidang sains dan teknologi. Fokus pada kontribusi orisinal para peneliti, akademisi, dan praktisi yang mengungkap pengetahuan baru, mengatasi tantangan, dan memajukan ...