INTENSIF: Jurnal Ilmiah Penelitian dan Penerapan Teknologi Sistem Informasi
Vol 10 No 2 (2026)

Network Infrastructure Security Audit at a Vocational School Teaching Factory Using the NIST Cybersecurity Framework

Maya Destriani (Universitas Subang)
Bintang Najarul Haq Mulyadi (Universitas Subang)
Tazkia Salsabila Ardan (Universitas Subang)



Article Info

Publish Date
22 Aug 2026

Abstract

Background: The increasing dependence on public-facing network services exposes educational institutions to growing cybersecurity threats, highlighting the need for structured security evaluations. This study evaluates cybersecurity maturity in a vocational school Teaching Factory (TEFA) environment using the NIST Cybersecurity Framework (NIST CSF) 1.1. Objective: To assess the cybersecurity maturity of the network infrastructure at TEFA TKJ SMK Al-Mufti, determine its implementation tier, and develop practical security improvements. Methods: A qualitative–quantitative descriptive case study was conducted using observations, interviews, questionnaires based on NIST CSF categories and subcategories, and document analysis. Risk assessment followed NIST SP 800-30, while gap analysis compared the Current Profile with a Target Profile defined at Tier 3 across the five NIST CSF core functions. Results: Although questionnaire results produced an average score of 3.45 (Tier 3), qualitative validation indicated that cybersecurity practices remained informal and inconsistently documented, resulting in an actual maturity level of Tier 2 (Risk Informed). A one-level gap was identified across all NIST CSF functions. Key risks included weak authentication, the absence of formal cybersecurity policies, and manual log monitoring. Implementing centralized log monitoring using Graylog improved visibility and strengthened the Detect and Respond functions. Conclusion: NIST CSF effectively identifies cybersecurity gaps and supports targeted improvements in educational network infrastructures. Further research should evaluate the long-term effectiveness of implemented controls and extend assessments to multiple institutions.

Copyrights © 2026






Journal Info

Abbrev

intensif

Publisher

Subject

Computer Science & IT Decision Sciences, Operations Research & Management

Description

INTENSIF Journal is a publication container for research in various fields related to information systems. These fields includeInformation System, Software Engineering, Data Mining, Data Warehouse, Computer Networking, Artificial Intelligence, e-Bussiness, e-Government, Big Data, Application ...