Digital transformation has positioned websites as critical components of public service delivery, data management, electronic transactions, and system integration, increasing the need for effective website security management that supports Indonesia's cybersecurity regulations. This study aims to analyze and prioritize website security risks by integrating the Penetration Testing Execution Standard (PTES), OWASP Top 10:2025, NIST SP 800-30, and the Analytic Hierarchy Process (AHP). A mixed-methods approach was employed by combining qualitative and quantitative analyses. Penetration testing was conducted using the PTES framework, and the identified vulnerabilities were classified according to OWASP Top 10:2025. Risk assessment was performed based on the likelihood and impact parameters defined in NIST SP 800-30, while AHP was applied to determine mitigation priorities. The results identified 28 security vulnerabilities consisting of 2 high-risk, 12 medium-risk, and 14 low-risk findings. The risk assessment results were subsequently integrated into a Laravel-based Decision Support System (DSS) that calculated criterion priority weights using AHP—with Impact (0.470859) as the most dominant criterion, followed by Exploitability (0.284013), Likelihood (0.171483), and Ease of Mitigation (0.073645)—thereby establishing an objective and measurable risk mitigation priority ranking. The proposed model supports website security decision-making, aligns with the risk management principles of ISO/IEC 27001, and has the potential to be adopted by other government institutions to strengthen information security governance.
Copyrights © 2026