Filter By Year

1945 2024


Found 1,293 documents
Search KEAMANAN INFORMASI

Modifikasi Keamanan Otentikasi OTP Menggunakan Algoritma HMAC-SHA256 pada Sistem Informasi PT Indonesia Gadai Oke Alvin Lie; Martiano Martiano
Jurnal Ilmu Komputer dan Sistem Informasi Vol. 5 No. 2 (2025): Mei 2026
Publisher : LKP Unity Academy

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.70340/jirsi.v5i2.346

Abstract

The security of user data in web-based information systems is frequently compromised by the weaknesses of conventional authentication mechanisms that rely solely on static passwords. Attacks such as credential theft and brute force on the internal information system of PT. Indonesia Gadai Oke necessitate an additional layer of security to protect sensitive customer data and financial transactions. This research aims to design and implement a Two-Factor Authentication (2FA) security system using the HMAC-SHA256 (Hash-based Message Authentication Code with Secure Hash Algorithm 256-bit) algorithm, integrated with Trusted Device features and Web Push notifications. The applied method is Time-based One-Time Password (TOTP) with a 30-second time interval. A unique code is generated on the server side through a 32-bit dynamic truncation process of the SHA-256 encryption result, which combines a secret key with a timestamp. Web Push Notification was chosen as the distribution medium to eliminate SMS operational costs and minimize delivery latency. System testing was conducted using Black Box Testing and Security Testing methods with a scenario of 10 experimental repetitions. The results indicate that the system achieved a 100% functional success rate in validating authorized users. In terms of security, the system proved effective in mitigating threats with a 100% success rate in rejecting SQL Injection, Cross-Site Scripting (XSS), and Replay Attacks through a single-use token validation mechanism. This implementation successfully reduced the risk of account hijacking and improved the efficiency of the authentication process at PT. Indonesia Gadai Oke.
Integrasi ISO 27001, Zero Trust, dan AI untuk Keamanan Sistem Informasi Keuangan Kampus Nina Mardiana; Yessica Fara Desvia; Angga Rahmat Pinanggih; Febryawan Yuda Pratama; Farah Diva Fadila
JURNAL PENELITIAN SISTEM INFORMASI (JPSI) Vol. 4 No. 2 (2026): Mei: JURNAL PENELITIAN SISTEM INFORMASI
Publisher : Institut Teknologi dan Bisnis (ITB) Semarang

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.54066/jpsi.v4i2.3879

Abstract

Financial information systems in higher education institutions manage highly sensitive assets, including tuition payments, scholarships, payroll, vendor transactions, budgeting, and institutional financial reporting. Although ISO/IEC 27001:2022 provides a risk-based foundation for establishing an Information Security Management System, its implementation in universities is frequently constrained by fragmented governance, limited resources, complex asset environments, inconsistent managerial commitment, cultural resistance, and limited real-time monitoring capability. This study aims to develop an integrated security evaluation model for campus financial information systems by combining ISO/IEC 27001:2022, Zero Trust Architecture, AI-driven threat detection, security maturity assessment, and human-factor analysis. The study adopts a mixed-method sequential explanatory design integrated with Design Science Research. Quantitative stages include asset identification, risk scoring, ISO 27001 control gap analysis, maturity assessment, Zero Trust readiness assessment, and AI-driven detection readiness assessment. Qualitative stages include document analysis, semi-structured interviews, observation, expert judgment, and thematic analysis to examine organizational, cultural, and behavioral factors influencing security control effectiveness. The proposed outcome is the HEFIS-ISMS Model, an integrated framework consisting of seven layers: ISO 27001 control compliance, risk-based asset protection, security maturity, human and organizational factors, Zero Trust readiness, AI-driven detection readiness, and improvement roadmap. The model is expected to address the static and compliance-oriented limitations of conventional ISO 27001 assessments by introducing adaptive access control, continuous monitoring, anomaly detection readiness, and phased implementation guidance. The study contributes theoretically to cybersecurity governance in higher education and practically to risk-prioritized security improvement for resource-constrained universities.
Pengembangan Sistem Keamanan Data Berbasis Blockchain untuk Perlindungan Informasi Sensitif di Sektor Keuangan Angga Rahmat Pinanggih; Nina Mardiana; Febryawan Yuda Pratama; Yessica Fara Desvia; Arman Maulana
JURNAL PENELITIAN SISTEM INFORMASI (JPSI) Vol. 4 No. 2 (2026): Mei: JURNAL PENELITIAN SISTEM INFORMASI
Publisher : Institut Teknologi dan Bisnis (ITB) Semarang

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.54066/jpsi.v4i2.3880

Abstract

The protection of sensitive information in the financial sector requires a security architecture capable of preserving confidentiality, integrity, availability, auditability, and regulatory accountability across multiple institutions. Conventional centralized security models remain vulnerable to single points of failure, unauthorized access, data manipulation, and limited transparency in inter-organizational data sharing. Blockchain offers tamper-resistant records, decentralized trust, and verifiable audit trails; however, its direct implementation in financial systems is constrained by scalability limitations, smart contract vulnerabilities, privacy leakage, and conflicts between immutable ledgers and data protection principles. This study aims to develop a blockchain-based data security system for protecting sensitive financial information by integrating permissioned blockchain and Zero-Knowledge Proofs. The proposed method adopts a consortium-oriented permissioned blockchain architecture, represented by Hyperledger Fabric, to ensure controlled participation, certificate-based identity management, endorsement policies, and auditable transaction validation. Smart contracts are designed as policy-enforcement components for consent management, access authorization, data commitment, revocation, and audit logging. Zero-Knowledge Proofs are incorporated to verify customer attributes, eligibility, and access rights without disclosing raw personal or financial data. Sensitive information is stored off-chain in encrypted form, while the blockchain records only cryptographic commitments, hashes, consent states, and audit events. The expected result is a security model that improves data integrity, controlled access, privacy-preserving verification, and compliance-oriented accountability while reducing unnecessary exposure of sensitive data on-chain. The implication of this research is the provision of a technically coherent framework for financial institutions seeking to adopt blockchain securely in regulated environments, especially where data confidentiality, auditability, and privacy compliance must be achieved simultaneously.
Analisis Tingkat Kematangan Keamanan Informasi Sistem Akademik Gapura Menggunakan COBIT 2019 (Fokus Domain APO13) Muhammad Hilal Lazuardi Toha; Fanny Risma Auliasari; Muhammad Nurudh Dholam; Tikno
KARMAPATI (Kumpulan Artikel Mahasiswa Pendidikan Teknik Informatika) Vol. 15 No. 2 (2026): Karmapati Vol 15 No 2 Tahun 2026
Publisher : Universitas Pendidikan Ganesha

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.23887/karmapati.v15i2.111234

Abstract

Keamanan informasi merupakan aspek penting dalam penerapan teknologi informasi di perguruan tinggi, khususnya pada sistem akademik yang mengelola data sensitif. Universitas XYZ telah mengimplementasikan Sistem GAPURA sebagai sistem terintegrasi untuk mendukung proses akademik dan administrasi. Seiring meningkatnya penggunaan sistem tersebut, potensi risiko keamanan informasi juga semakin besar sehingga diperlukan evaluasi tingkat kematangan pengelolaannya. Penelitian ini bertujuan untuk menganalisis tingkat kematangan keamanan informasi pada Sistem GAPURA Universitas XYZ menggunakan kerangka kerja COBIT 2019 dengan fokus pada domain APO13 (Manage Security). Metode penelitian yang digunakan adalah deskriptif kuantitatif dengan teknik pengumpulan data melalui kuesioner capability level, wawancara, dan studi dokumentasi yang melibatkan unit pengelola teknologi informasi. Penilaian dilakukan pada subproses APO13.01, APO13.02, dan APO13.03. Hasil penelitian menunjukkan bahwa nilai capability level rata-rata sebesar 0,26 yang berada pada kategori Level 0 (Incomplete). Target capability level yang diharapkan adalah Level 3, sehingga terdapat gap sebesar tiga level. Selain itu, nilai maturity level juga berada pada Level 0 dengan target maturity level sebesar Level 2, yang menunjukkan adanya gap dua level. Temuan ini mengindikasikan bahwa pengelolaan keamanan informasi pada Sistem GAPURA belum berjalan secara terstruktur dan terdokumentasi. Oleh karena itu, diperlukan rekomendasi perbaikan berupa penyusunan kebijakan keamanan informasi, pengelolaan risiko, serta penerapan monitoring dan evaluasi keamanan informasi secara berkelanjutan sesuai dengan COBIT 2019.
Analisis Keamanan Sistem Informasi Website Kampus Menggunakan Metode Penetration Test I Kadek Ryan Jody Prayoga; Putu Wida Gunawan; I Nyoman Bernadus
SemanTIK : Teknik Informasi Vol. 11 No. 2 (2025): SemanTIK : Teknik Informasi
Publisher : Informatics Engineering Department of Halu Oleo University

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.55679/semantik.v11i2.212

Abstract

SIISTA (Single Integrated Information System Undhira) adalah salah satu sistem informasi pengelolaan data dan penyedia layanan kampus yang belum diuji keamanan dan kerentanan sistemnya dari serangan siber, sehingga dibutuhkan upaya untuk memastikan dan menganalisis keamanan sistem dari potensi ancaman serangan siber. Penelitian ini bertujuan untuk menganalisis dan menguji sistem informasi SIISTA dengan menggunakan metode penetration testing dengan melakukan XSS injection dan percobaan brute force pada sistem. Metode penetration testing melalui lima tahapan utama yaitu perencanaan, pengumpulan informasi, analisis kerentanan, eksploitasi, pemeliharaan akses dan analisis hasil. Tools yang digunakan dalam proses ini antara lain Nmap, burp suite, OWASP ZAP, dan metasploit framework. Hasil pengujian menunjukkan adanya kerentanan pada sistem, yaitu kerentanan reflected XSS persistent-effect, reflected XSS, dan penggunaan JS library versi lama yang rentan terhadap eksploitasi dan serangan siber. Selain itu, hasil eksploitasi tidak menemukan akses tidak sah ke dalam sistem secara langsung, namun potensi dari serangan terhadap input pengguna tetap tinggi dan bisa dimanfaatkan untuk phishing atau pencurian data. Berdasarkan hasil pengujian, kesimpulannya adalah sistem informasi SIISTA masih memiliki kerentanan yang dapat dimanfaatkan oleh pihak yang tidak bertanggung jawab, meskipun tidak ada akses langsung yang berhasil diperoleh kedalam sistem, kerentanan sanitasi input atau XSS pada sistem dapat dimanfaatkan secara berulang. SIISTA (Single Integrated Information System Undhira) is a campus data management and service information system that has not yet undergone security and vulnerability testing against potential cyberattacks. Therefore, it is necessary to evaluate and analyze the system’s security to identify possible threats. This study aims to assess the security of the SIISTA information system using the penetration testing method by performing XSS injections and brute-force attempts. The penetration testing process follows five main phases: planning, information gathering, vulnerability analysis, exploitation, access maintenance, and reporting. The tools used in this process include Nmap, Burp Suite, OWASP ZAP, and the Metasploit Framework. The results indicate the presence of several vulnerabilities in the system, such as reflected XSS with persistent effect, standard reflected XSS, and the use of outdated JavaScript libraries that are susceptible to exploitation and cyberattacks. While no unauthorized access to the system was achieved during exploitation, the high potential for attacks targeting user input could lead to phishing or data theft. Based on the findings, it can be concluded that the SIISTA information system still contains vulnerabilities that may be exploited by malicious parties. Although direct access to the system was not obtained, input sanitization flaws such as XSS can be repeatedly exploited.
Penyuluhan Keamanan Data Pribadi Dalam Penggunaan Sistem Informasi Online Pada Masyarakat Kelurahan Tettikenrarae Kecamatan Marioriwawo Kabupaten Soppeng Karanita; Andi Zulkifli Nusri; Sukriani; Baso Sutrisno; Alex Sandri Sikumbang
Journal of Golden Generation Abdimas Vol. 2 No. 1 (2026): Maret : Journal of Golden Generation Abdimas
Publisher : PT. Lembaga Penerbit Penelitian Nusantara

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.65244/jgga.v2i1.460

Abstract

Perkembangan teknologi informasi dan komunikasi telah mendorong pemanfaatan sistem informasi online dalam pelayanan publik di tingkat kelurahan. Namun, peningkatan penggunaan teknologi tersebut juga menimbulkan risiko terhadap keamanan data pribadi masyarakat. Kegiatan pengabdian masyarakat ini bertujuan untuk meningkatkan pengetahuan, kesadaran, dan keterampilan masyarakat Kelurahan Tettikenrarae, Kecamatan Marioriwawo, Kabupaten Soppeng dalam melindungi data pribadi saat menggunakan sistem informasi online. Metode yang digunakan adalah penyuluhan dengan pendekatan partisipatif melalui tahapan koordinasi, observasi, penyampaian materi, diskusi interaktif, dan evaluasi. Kegiatan dilaksanakan selama satu hari dengan melibatkan masyarakat setempat. Hasil kegiatan menunjukkan adanya peningkatan pemahaman peserta mengenai jenis data pribadi, potensi ancaman keamanan digital seperti phishing dan penyalahgunaan data, serta langkah-langkah perlindungan yang dapat diterapkan dalam aktivitas digital sehari-hari. Antusiasme peserta dan dukungan pemerintah kelurahan menjadi faktor pendukung utama keberhasilan kegiatan ini, meskipun masih terdapat kendala berupa perbedaan tingkat literasi digital dan keterbatasan sarana pendukung. Secara keseluruhan, penyuluhan ini berkontribusi dalam memperkuat literasi digital masyarakat serta mendukung terwujudnya tata kelola pemerintahan berbasis digital yang aman dan berkelanjutan.
Analisis Kesiapan Keamanan Informasi DISKOMINFO Kota Jambi Menggunakan Indeks KAMI Usman Kamaruddin; Daniel Arsa; Mutia Fadhila Putri
Jurnal Nasional Komputasi dan Teknologi Informasi Vol. 9 No. 2 (2026): April, 2026
Publisher : Program Studi Teknik Komputer, Fakultas Teknik. Universitas Serambi Mekkah

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.32672/1f0kgz74

Abstract

Abstrak - Penelitian ini bertujuan untuk menganalisis tingkat kesiapan keamanan informasi Dinas Komunikasi dan Informatika (DISKOMINFO) Kota Jambi menggunakan Indeks KAMI (Keamanan Informasi) versi 5.0. Indeks KAMI merupakan alat evaluasi yang dikembangkan oleh BSSN berdasarkan standar SNI ISO/IEC 27001. Penelitian dilakukan melalui wawancara langsung dengan lima responden yang merupakan kepala bidang atau perwakilan dari setiap bidang di DISKOMINFO Kota Jambi menggunakan metode snowball sampling. Data divalidasi menggunakan teknik triangulasi. Hasil evaluasi menunjukkan bahwa DISKOMINFO Kota Jambi memperoleh total skor 343 dari skor maksimum 645, yang menempatkannya pada kategori tidak layak. Penilaian dilakukan pada delapan area yaitu kategori sistem elektronik (20 poin), tata kelola keamanan informasi (35 poin), pengelolaan risiko (16 poin), kerangka kerja keamanan informasi (49 poin), pengelolaan aset informasi (94 poin), teknologi dan keamanan informasi (121 poin), perlindungan data pribadi (28 poin), dan suplemen (42%). Area teknologi dan keamanan informasi memperoleh skor tertinggi, sementara area pengelolaan risiko memperoleh skor terendah. Penelitian ini merekomendasikan penguatan kebijakan keamanan informasi, implementasi manajemen risiko sistematis, serta peningkatan kapasitas sumber daya manusia sesuai dengan standar ISO/IEC 27001. Kata kunci : Keamanan Informasi; Indeks KAMI; DISKOMINFO; ISO/IEC 27001; Evaluasi Kesiapan; Abstract - This study aims to analyze the information security readiness level of the Communication and Information Service (DISKOMINFO) of Jambi City using the KAMI Index (Information Security) version 5.0. The KAMI Index is an evaluation tool developed by BSSN based on the SNI ISO/IEC 27001 standard. The research was conducted through direct interviews with five respondents who are heads of divisions or representatives from each division in DISKOMINFO Jambi City using the snowball sampling method. Data were validated using triangulation techniques. The evaluation results show that DISKOMINFO Jambi City obtained a total score of 343 out of a maximum score of 645, placing it in the not-eligible category. The assessment was conducted on eight areas: electronic system category (20 points), information security governance (35 points), risk management (16 points), information security framework (49 points), information asset management (94 points), technology and information security (121 points), personal data protection (28 points), and supplement (42%). The technology and information security area obtained the highest score, while the risk management area obtained the lowest score. This study recommends strengthening information security policies, implementing systematic risk management, and improving human resource capacity in accordance with ISO/IEC 27001 standards. Keywords: Information Security; KAMI Index; DISKOMINFO; ISO/IEC 27001; Readiness Evaluation;
Tantangan Keamanan Informasi Pada Era Cloud Computing: Analisis Literatur Mengenai Strategi Kontrol dan Mitigasi Risiko Imam Ariq Rizqy; Aril Sharon Saragih
Jurnal Ilmu Ekonomi dan Bisnis Vol 4 No 2 (2026): Oktober, Jurnal Ilmu Ekonomi dan Bisnis
Publisher : Perkumpulan Konsultan Manajemen Pendidikan Indonesia (PKMPI)

Show Abstract | Download Original | Original Source | Check in Google Scholar

Abstract

The development of cloud computing has transformed the way organizations stored, managed, and accessed information by providing more flexible and efficient technology services. At the same time, the adoption of this technology has introduced various information security challenges, including the risks of data breaches, unauthorized access, data loss, and increasingly sophisticated cyber threats. This study aimed to analyze the information security challenges in the era of cloud computing and to identify control strategies and risk mitigation measures based on a literature review. The study employed a qualitative approach using a literature review method by examining relevant scholarly articles, books, and academic publications. The findings indicated that securing cloud computing environments was not determined solely by the use of technology but also by the implementation of comprehensive controls, including identity and access management, data protection through encryption, continuous security monitoring, security auditing, and consistent risk management practices. In addition, increasing user awareness and implementing effective information security governance contributed to reducing potential threats and strengthening the protection of information assets. The study concluded that the combination of technical controls, organizational policies, and continuous risk management played a crucial role in maintaining the confidentiality, integrity, and availability of information within cloud computing environments.
PERAN SISTEM INFORMASI MANAJEMEN DALAM PENERAPAN DATA MASKING UNTUK MENINGKATKAN KEAMANAN DATA RESI PADA E – COMMERCE Rayyan Firdaus; Chayara Alima Qanita; Dini Aulia
Jurnal Riset Sistem Informasi Vol. 3 No. 4 (2026): Oktober: Jurnal Riset Sistem Informasi
Publisher : CV. Denasya Smart Publisher

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.69714/mqdzaw66

Abstract

The rapid growth of e-commerce has increased the volume of customer data, including sensitive shipping receipt data. However, data protection in this sector remains suboptimal, making the risk of personal data leakage a serious threat. This study aims to analyze the role of Management Information Systems (MIS) in supporting the implementation of data masking to improve the security of receipt data on e-commerce platforms. The method used is a literature study with a qualitative approach, reviewing various scientific sources published between 2021 and 2026. The results show that MIS plays an important role in three main aspects: RBAC-based access restrictions, AI/NLP-based sensitive data sorting, and dynamic data masking on the interface without altering the original data. In addition, MIS also maintains smooth post-masking operations by maintaining the data format. The implementation of MIS-based data masking has proven effective in improving receipt data security, as demonstrated in previous research. Thus, MIS and data masking are strategic, complementary solutions in protecting customer privacy in the digital era.
Penilaian Keamanan Informasi Di Rumah Sakit Panti Wilasa Citarum Berdasar Indeks KAMI 5.0 Kurniadi, Arif; Reandra Permana, Alpha; Wardoyo, Agung
Jurnal Informatika UPGRIS Vol 12, No 1: Juni 2026
Publisher : Universitas PGRI Semarang

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.26877/jiu.v12i1.27316

Abstract

Regulation Number 24 of 2022 by the Minister of Health of the Republic of Indonesia addresses Data Security and Protection. The Panti Wilasa Citarum Hospital follows Hospital Accreditation Commision quality standards, particularly regarding MRMIK 13 which covers information technology regulations. The hospital assesses its information security readiness using the KAMI Index from BSSN, aligned with ISO/IEC 27001 standards, to evaluate the level of information security as it implements Electronic Medical Records.  The study involved a questionnaire from four respondents and interviews with the IT head. Results showed the following scores: electronic system category received 20 points (High), Governance 41 points (Maturity Level I plus), Risk Management 35 points (Level II), Information Security Framework 61 points (Level I plus), Asset Management 176 points (Level II), Information Security Technology 131 points (Level II), Personal Data Protection 60 points (Level II), and Third Party Security at 53%. The overall score was 504 points, reflecting a "Basic Framework Compliance" at Maturity Level II, which did not meet KAMI Index requirements. The hospital must enhance information security through training, awareness, and periodic assessments.

Page 123 of 130 | Total Record : 1293