Jurnal Sistem Informasi Galuh
Vol 4 No 2 (2026): Journal of Galuh Information Systems

VULNERABILITY ASSESSMENT PADA SISTEM PEMERINTAHAN BERBASIS ELEKTRONIK (SPBE) MENGGUNAKAN OWASP TOP 10

La Ode Muhamad Azhraf (Universitas Jenderal Achmad Yani)
Mamay Syani (Politeknik TEDC Bandung)
Devan Christovano Prabowo (Universitas Jenderal Achmad Yani)
Irma Santikarama (Universitas Jenderal Achmad Yani)
Faiza Renaldi (Universitas Jenderal Achmad Yani)



Article Info

Publish Date
11 Jul 2026

Abstract

The implementation of Electronic-Based Government Systems (SPBE) increases the dependence of public services on web applications, making application security an essential aspect of digital governance. This study was conducted to identify, classify, and provide mitigation recommendations for security vulnerabilities in two public web applications managed in the Cimahi City government environment, namely XYZ Regional Office Application and XYZ Subdistrict Website. The research used a non-disruptive Vulnerability Assessment approach based on the Open Worldwide Application Security Project (OWASP) Top 10 framework, supported by OWASP Zed Attack Proxy (ZAP), Burp Suite Pro, and manual validation of request-response evidence. The assessment identified 24 valid findings, consisting of 6 Medium, 11 Low, and 7 Informational findings. The dominant vulnerability category was A05: Security Misconfiguration, including missing security headers, server information disclosure, weak cookie attributes, and incomplete transport security configuration. XYZ Regional Office Application became the main mitigation priority because its login form still used HTTP. These findings highlight the need for HTTPS enforcement, HSTS activation, CSP implementation, cookie hardening, outdated component updates, and periodic security assessment.

Copyrights © 2026






Journal Info

Abbrev

jsig

Publisher

Subject

Computer Science & IT

Description

JSIG (Jurnal Sistem Informasi Galuh) dimaksudkan sebagai media kajian ilmiah hasil penelitian, pemikiran, dan kajian kritis-analitik mengenai penelitian di bidang ilmu dan teknologi komputer, termasuk Teknik Sistem, Teknik Informatika/Teknologi Informasi, Informatika Manajemen, dan Sistem Informasi. ...