Indonesian Journal of Information System
Vol. 9 No. 1 (2026): August 2026

Integrating the NIST 800-30 Risk Management Framework with Penetration Testing: A Case Study of Web-Based Training Information Systems in a Cybersecurity Company

Yohanes Dewantara Marpaung (Information Systems Department, Universitas Kristen Duta Wacana, Yogyakarta)
Halim Budi Santoso (Universitas Kristen Duta Wacana)
Erick Kurniawan (Information System Department, Universitas Kristen Duta Wacana, Yogyakarta)
Gabriel Indra Widi Tamtama (Institute of Service Science, College of Technology Management, National Tsing Hua University, Hsinchu City, Taiwan)
Abdul Karim (Cerebrovascular Disease Research Center and Department of Artificial Intelligence Convergence, Hallym University, Chuncheon, Gangwon, South Korea)



Article Info

Publish Date
31 Aug 2026

Abstract

Web application security has become a paramount concern due to the escalating frequency of cyber threats targeting internet-based information systems. Web developers must prioritize risk management, with a particular emphasis on integrating risk identification within the information security management system. Companies specializing in information security management must exercise caution when deploying web-based applications, as information security is a critical issue that can substantially affect a company's reputation. However, previous research has frequently failed to address this issue comprehensively. Consequently, this study seeks to investigate the integration of a risk management framework with penetration testing. The amalgamation of penetration testing with NIST SP 800-30 is expected to provide a comprehensive risk assessment. The penetration testing was conducted using a grey-box testing methodology, guided by OWASP WSTG v4.2 and augmented by CVSS v3.1 for severity measurement. Subsequently, NIST SP 800-30 was employed as the risk management framework. The grey-box testing was performed on a recently deployed web-based training management system. As a result, four vulnerabilities were identified and verified through Proof of Concept: SQL Injection (High), Blind Stores XSS (Critical), Unrestricted file upload enabling remote code execution (Critical), and Brute Force Attack (High). A comprehensive risk identification and mitigation process was then conducted for these vulnerabilities. This study also provides improvement suggestions to aid in mitigating the identified vulnerabilities. This research introduces a novel approach by integrating penetration testing with risk management frameworks to enhance the effectiveness of risk management in web-based applications

Copyrights © 2026