Web application security has become a paramount concern due to the escalating frequency of cyber threats targeting internet-based information systems. Web developers must prioritize risk management, with a particular emphasis on integrating risk identification within the information security management system. Companies specializing in information security management must exercise caution when deploying web-based applications, as information security is a critical issue that can substantially affect a company's reputation. However, previous research has frequently failed to address this issue comprehensively. Consequently, this study seeks to investigate the integration of a risk management framework with penetration testing. The amalgamation of penetration testing with NIST SP 800-30 is expected to provide a comprehensive risk assessment. The penetration testing was conducted using a grey-box testing methodology, guided by OWASP WSTG v4.2 and augmented by CVSS v3.1 for severity measurement. Subsequently, NIST SP 800-30 was employed as the risk management framework. The grey-box testing was performed on a recently deployed web-based training management system. As a result, four vulnerabilities were identified and verified through Proof of Concept: SQL Injection (High), Blind Stores XSS (Critical), Unrestricted file upload enabling remote code execution (Critical), and Brute Force Attack (High). A comprehensive risk identification and mitigation process was then conducted for these vulnerabilities. This study also provides improvement suggestions to aid in mitigating the identified vulnerabilities. This research introduces a novel approach by integrating penetration testing with risk management frameworks to enhance the effectiveness of risk management in web-based applications
Copyrights © 2026