RABIT: Jurnal Teknologi dan Sistem Informasi Univrab
Vol 11 No 1 (2026): Januari

PERANCANGAN SISTEM INFORMASI WEBSITE DESA UNTUK PELAYANAN SURAT-MENYURAT DENGAN PENDEKATAN SECURE SOFTWARE DEVELOPMENT LIFE CYCLE (SSDLC)

MONA RATULIU (Program Studi Keamanan Sistem Informasi, Politeknik Negeri Bengkalis)
Nurmi Hidayasari (Politeknik Negeri Bengkalis)



Article Info

Publish Date
05 Mar 2026

Abstract

Correspondence administration services are one of the primary services provided by village governments to the community. However, in Teluk Lancar Village, the correspondence service process is still carried out manually, resulting in various issues such as service delays, data recording errors, and potential security risks to community data. In addition, the manual system makes it difficult for the community to monitor the status of submitted correspondence requests. This study aims to design and implement a village website information system for correspondence services by applying the Secure Software Development Life Cycle (SSDLC) approach with a focus on improving system security. The implementation of SSDLC in this study focuses on three main stages, namely Secure Design, Secure Coding, and Security Testing. In the Secure Design stage, the system is designed by implementing Role-Based Access Control (RBAC) to restrict user access based on the roles of community members, operators, and village administrators. The Secure Coding stage is implemented through role-based access control, input validation, and page access protection to prevent unauthorized access. Furthermore, the Security Testing stage is conducted using OWASP ZAP to identify potential security vulnerabilities in the system. The results show that the RBAC mechanism has been successfully implemented and is able to restrict user access according to their roles. Security testing results indicate the presence of vulnerabilities categorized as High, Medium, Low, and Informational, with the majority classified as low risk. The identified high-risk finding is related to application security misconfiguration (missing security headers), which does not directly affect data confidentiality but serves as an important basis for security evaluation and remediation in subsequent development stages.

Copyrights © 2026






Journal Info

Abbrev

rabit

Publisher

Subject

Computer Science & IT Engineering

Description

This journal is called RABIT, where the name comes from two words namely, RAB which means Abdurrab University and IT which means information technology, it can be interpreted as a journal of this journal Journal of Informatics Engineering Study Program Pekanbaru Abdurrab University. This RABIT ...