Integrating the NIST 800-30 Risk Management Framework with Penetration Testing: A Case Study of Web-Based Training Information Systems in a Cybersecurity Company

Authors

  • Yohanes Dewantara Marpaung Information Systems Department, Universitas Kristen Duta Wacana, Yogyakarta
  • Halim Budi Santoso Universitas Kristen Duta Wacana
  • Erick Kurniawan Information System Department, Universitas Kristen Duta Wacana, Yogyakarta
  • Gabriel Indra Widi Tamtama Institute of Service Science, College of Technology Management, National Tsing Hua University, Hsinchu City, Taiwan
  • Abdul Karim Cerebrovascular Disease Research Center and Department of Artificial Intelligence Convergence, Hallym University, Chuncheon, Gangwon, South Korea

DOI:

https://doi.org/10.24002/ijis.v9i1.14877

Abstract

Web application security has become a paramount concern due to the escalating frequency of cyber threats targeting internet-based information systems. Web developers must prioritize risk management, with a particular emphasis on integrating risk identification within the information security management system. Companies specializing in information security management must exercise caution when deploying web-based applications, as information security is a critical issue that can substantially affect a company's reputation. However, previous research has frequently failed to address this issue comprehensively. Consequently, this study seeks to investigate the integration of a risk management framework with penetration testing. The amalgamation of penetration testing with NIST SP 800-30 is expected to provide a comprehensive risk assessment. The penetration testing was conducted using a grey-box testing methodology, guided by OWASP WSTG v4.2 and augmented by CVSS v3.1 for severity measurement. Subsequently, NIST SP 800-30 was employed as the risk management framework. The grey-box testing was performed on a recently deployed web-based training management system. As a result, four vulnerabilities were identified and verified through Proof of Concept: SQL Injection (High), Blind Stores XSS (Critical), Unrestricted file upload enabling remote code execution (Critical), and Brute Force Attack (High). A comprehensive risk identification and mitigation process was then conducted for these vulnerabilities. This study also provides improvement suggestions to aid in mitigating the identified vulnerabilities. This research introduces a novel approach by integrating penetration testing with risk management frameworks to enhance the effectiveness of risk management in web-based applications

References

[1] Safitra, M.F., Lubis, M., and Widjajarto, A.: ‘Security vulnerability analysis using penetration testing execution standard (PTES): case study of government's website’, in Editor (Ed.)^(Eds.): ‘Book Security vulnerability analysis using penetration testing execution standard (PTES): case study of government's website’ (2023, edn.), pp. 139-145

[2] Wibowo, R.M., and Sulaksono, A.: ‘Web vulnerability through Cross Site Scripting (XSS) detection with OWASP security shepherd’, Indonesian Journal of Information Systems, 2021, 3, (2), pp. 149-159

[3] Egbedion, G.E.: ‘Impact of vulnerability management and penetration testing on security-informed IT project planning and implementation’, Journal of Multidisciplinary Engineering Science and Technology (JMEST), 2024

[4] Isnaini, K., Asyari, M.H., Amrillah, S.F., and Suhartono, D.: ‘Vulnerability Assessment and Penetration Testing on Student Service Center System’, ILKOM Jurnal Ilmiah, 2024, 16, (2), pp. 161-171

[5] Ajufo, G., and Qutieshat, A.: ‘An examination of the human factors in cybersecurity: Future direction for Nigerian banks’, Indonesian Journal of Information Systems, 2023, 6, (1), pp. 1-16

[6] Wichmann, P., Groddeck, A., and Federrath, H.: ‘Fileuploadchecker: detecting and sanitizing malicious file uploads in web applications at the request level’, in Editor (Ed.)^(Eds.): ‘Book Fileuploadchecker: detecting and sanitizing malicious file uploads in web applications at the request level’ (2022, edn.), pp. 1-10

[7] Lubis, M., Luthfi, M.I., Saedudin, R.R., Muttaqin, A.N., and Lubis, A.R.: ‘The Integration of ISO 27005 and NIST SP 800-30 for Security Operation Center (SOC) Framework Effectiveness in the Non-Bank Financial Industry’, Computers, 2026, 15, (1), pp. 60

[8] Pambudi, R.D., and Ramli, K.: ‘Information Security Risk Management Design of Supervision Management Information System At Xyz Ministry Using Nist Sp 800-30’, Jurnal Teknik Informatika (Jutif), 2023, 4, (3), pp. 591-599

[9] Wang, J.-C., Hong, Y.-J., Sanjaya, E., and Santoso, H.B.: ‘Engaging or Silent? Social Media Commenting on Controversial versus Uncontroversial Issues’, Pacific Asia Journal of the Association for Information Systems, 2024, 17, (2), pp. 1-7

[10] Wang, J.-C., Hung, Y.-C., and Santoso, H.B.: ‘How ESL Devices Transform into Connected Label Solutions: A Perspective of Actor Interaction and Information Rebundling’, NTU Management Review, 2024, 34, (3), pp. 229-286

[11] Windasari, N.A., and Santoso, H.B.: ‘Multichannel Retailing in Beauty Product: Understanding Customer Purchase Decisions between Offline Stores, Websites, and Augmented Reality’, Jurnal Sistem Informasi, 2022, 18, (2), pp. 50-67

[12] Priambodo, D.F., Rifansyah, A.D., and Hasbi, M.: ‘Web XYZ Penetration Testing using OWASP Risk Rating [Penetration testing Web XYZ berdasarkan OWASP risk rating]’, Teknika, 2023, 12, (1), pp. 33-46

[13] Tinambunan, F., Junaidi, A., and Rizki, A.M.: ‘Academic Information Testing of the University X using Penetration Testing based on Owasp Top 10 [Pengujian Sistem Informasi Akademik Universitas X Melalui Pendekatan Penetration Testing Berdasarkan Owasp Top 10]’, JATI (Jurnal Mahasiswa Teknik Informatika), 2024, 8, (1), pp. 1062-1069

[14] Rozali, M., and Sinaga, M.D.: ‘Web Security Diagnosis using Penetration Testing of a School Website [Diagnosis Keamanan Web Menggunakan Metode Uji Penetrasi Website Sekolah]’, Jurnal Info Digit (JID), 2024, 2, (1), pp. 246-262

[15] Lina, I.M.: ‘Anticipate password security with burp suite using the brute force attack method’, Jurnal E-Komtek, 2023, 7, (1), pp. 118-127

[16] El Marzak, Y., Chahid, A., Faris, S., and Mansouri, K.: ‘Developing a Unified Cyber Risk Management Framework Using Semantic Technologies and Structured Modeling Approaches’, Engineering, Technology & Applied Science Research, 2026, 16, (1), pp. 31043-31051

[17] Mızrak, F.: ‘Integrating cybersecurity risk management into strategic management: a comprehensive literature review’, Research Journal of Business and Management, 2023, 10, (3), pp. 98-108

[18] Syafitri, W.: ‘Information Security Risk Assessment using NIST 800-30 (Case Study: Academic Information Systes University XYZ) [Penilaian Risiko Keamanan Informasi Menggunakan Metode NIST 800-30 (Studi Kasus: Sistem Informasi Akademik Universitas XYZ)]’, Jurnal CoreIT, 2016, 2, (2), pp. 8-13

[19] Kurniawan, D.K.C., and Sihotang, J.I.: ‘NIST 800-30 Risk Assessment Audit for Academic Excellence: A Roadmap for Strengthening Cybersecurity at Universitas Advent Indonesia’, TeIKa, 2025, 15, (2), pp. 63-77

[20] Prasetyo, B., Salsabila, A., and Retnani, W.E.Y.: ‘IT Risk Management Analysis Based on ISO 31000 and Bow Tie Analysis (BTA) in Higher Education Institution’, Indonesian Journal of Information Systems, 2024, 7, (1), pp. 84-96

[21] Raihan, S.D., Prabowo, S., and Oktaria, D.: ‘Security Vulnerable Evaluation of a Web Application with Vulnerability Assessment and Penetration Testing using OWASP and NIST SP 800-30 Revision 1 [Evaluasi Risiko Celah Keamanan Pada Aplikasi Web Dengan Penilaian Kerentanan dan Pengujian Penetrasi Menggunakan Metode OWASP dan NIST SP 800-30 Revisi 1]’, LOGIC: Jurnal Penelitian Informatika, 2024, 2, (2)

[22] Monageng, T., and Esiefarienrhe, B.M.: ‘Analysis of Risk Assessment Framework Using Agile Methodology and Computer-Aided Software Engineering Tools’, Indonesian Journal of Information Systems, 2026, 8, (2), pp. 157-174

[23] Acharya, S., and Pandya, V.: ‘Bridge between black Box and white Box–gray Box testing technique’, International Journal of Electronics and Computer Science Engineering, 2012, 2, (1), pp. 175-185

[24] Muna, S.R., Santoso, H.B., and Siang, J.J.: ‘Internal Compliance Audit of the Information Security Management System in a Cybersecurity Company based on ISO/IEC 27001’, Sistemasi: Jurnal Sistem Informasi, 2026, 15, (6), pp. 2267-2278

[25] Dewanti, A.C., Santoso, H.B., and Siang, J.J.: ‘ISO 27001 Annex A Compliance Analysis of a Cybersecurity Company [Analisis Kepatuhan ISO 27001 Annex A pada Perusahaan Keamanan Siber]’, Jutisi: Jurnal Ilmiah Teknik Informatika dan Sistem Informasi, 2026, 15, (3), pp. 996-1007

Downloads

Published

2026-08-31

How to Cite

Yohanes Dewantara Marpaung, Halim Budi Santoso, Erick Kurniawan, Gabriel Indra Widi Tamtama, & Abdul Karim. (2026). Integrating the NIST 800-30 Risk Management Framework with Penetration Testing: A Case Study of Web-Based Training Information Systems in a Cybersecurity Company. Indonesian Journal of Information Systems, 9(1), 90–106. https://doi.org/10.24002/ijis.v9i1.14877

Issue

Section

Articles