Integrating the NIST 800-30 Risk Management Framework with Penetration Testing: A Case Study of Web-Based Training Information Systems in a Cybersecurity Company
DOI:
https://doi.org/10.24002/ijis.v9i1.14877Abstract
Web application security has become a paramount concern due to the escalating frequency of cyber threats targeting internet-based information systems. Web developers must prioritize risk management, with a particular emphasis on integrating risk identification within the information security management system. Companies specializing in information security management must exercise caution when deploying web-based applications, as information security is a critical issue that can substantially affect a company's reputation. However, previous research has frequently failed to address this issue comprehensively. Consequently, this study seeks to investigate the integration of a risk management framework with penetration testing. The amalgamation of penetration testing with NIST SP 800-30 is expected to provide a comprehensive risk assessment. The penetration testing was conducted using a grey-box testing methodology, guided by OWASP WSTG v4.2 and augmented by CVSS v3.1 for severity measurement. Subsequently, NIST SP 800-30 was employed as the risk management framework. The grey-box testing was performed on a recently deployed web-based training management system. As a result, four vulnerabilities were identified and verified through Proof of Concept: SQL Injection (High), Blind Stores XSS (Critical), Unrestricted file upload enabling remote code execution (Critical), and Brute Force Attack (High). A comprehensive risk identification and mitigation process was then conducted for these vulnerabilities. This study also provides improvement suggestions to aid in mitigating the identified vulnerabilities. This research introduces a novel approach by integrating penetration testing with risk management frameworks to enhance the effectiveness of risk management in web-based applications
References
[1] Safitra, M.F., Lubis, M., and Widjajarto, A.: ‘Security vulnerability analysis using penetration testing execution standard (PTES): case study of government's website’, in Editor (Ed.)^(Eds.): ‘Book Security vulnerability analysis using penetration testing execution standard (PTES): case study of government's website’ (2023, edn.), pp. 139-145
[2] Wibowo, R.M., and Sulaksono, A.: ‘Web vulnerability through Cross Site Scripting (XSS) detection with OWASP security shepherd’, Indonesian Journal of Information Systems, 2021, 3, (2), pp. 149-159
[3] Egbedion, G.E.: ‘Impact of vulnerability management and penetration testing on security-informed IT project planning and implementation’, Journal of Multidisciplinary Engineering Science and Technology (JMEST), 2024
[4] Isnaini, K., Asyari, M.H., Amrillah, S.F., and Suhartono, D.: ‘Vulnerability Assessment and Penetration Testing on Student Service Center System’, ILKOM Jurnal Ilmiah, 2024, 16, (2), pp. 161-171
[5] Ajufo, G., and Qutieshat, A.: ‘An examination of the human factors in cybersecurity: Future direction for Nigerian banks’, Indonesian Journal of Information Systems, 2023, 6, (1), pp. 1-16
[6] Wichmann, P., Groddeck, A., and Federrath, H.: ‘Fileuploadchecker: detecting and sanitizing malicious file uploads in web applications at the request level’, in Editor (Ed.)^(Eds.): ‘Book Fileuploadchecker: detecting and sanitizing malicious file uploads in web applications at the request level’ (2022, edn.), pp. 1-10
[7] Lubis, M., Luthfi, M.I., Saedudin, R.R., Muttaqin, A.N., and Lubis, A.R.: ‘The Integration of ISO 27005 and NIST SP 800-30 for Security Operation Center (SOC) Framework Effectiveness in the Non-Bank Financial Industry’, Computers, 2026, 15, (1), pp. 60
[8] Pambudi, R.D., and Ramli, K.: ‘Information Security Risk Management Design of Supervision Management Information System At Xyz Ministry Using Nist Sp 800-30’, Jurnal Teknik Informatika (Jutif), 2023, 4, (3), pp. 591-599
[9] Wang, J.-C., Hong, Y.-J., Sanjaya, E., and Santoso, H.B.: ‘Engaging or Silent? Social Media Commenting on Controversial versus Uncontroversial Issues’, Pacific Asia Journal of the Association for Information Systems, 2024, 17, (2), pp. 1-7
[10] Wang, J.-C., Hung, Y.-C., and Santoso, H.B.: ‘How ESL Devices Transform into Connected Label Solutions: A Perspective of Actor Interaction and Information Rebundling’, NTU Management Review, 2024, 34, (3), pp. 229-286
[11] Windasari, N.A., and Santoso, H.B.: ‘Multichannel Retailing in Beauty Product: Understanding Customer Purchase Decisions between Offline Stores, Websites, and Augmented Reality’, Jurnal Sistem Informasi, 2022, 18, (2), pp. 50-67
[12] Priambodo, D.F., Rifansyah, A.D., and Hasbi, M.: ‘Web XYZ Penetration Testing using OWASP Risk Rating [Penetration testing Web XYZ berdasarkan OWASP risk rating]’, Teknika, 2023, 12, (1), pp. 33-46
[13] Tinambunan, F., Junaidi, A., and Rizki, A.M.: ‘Academic Information Testing of the University X using Penetration Testing based on Owasp Top 10 [Pengujian Sistem Informasi Akademik Universitas X Melalui Pendekatan Penetration Testing Berdasarkan Owasp Top 10]’, JATI (Jurnal Mahasiswa Teknik Informatika), 2024, 8, (1), pp. 1062-1069
[14] Rozali, M., and Sinaga, M.D.: ‘Web Security Diagnosis using Penetration Testing of a School Website [Diagnosis Keamanan Web Menggunakan Metode Uji Penetrasi Website Sekolah]’, Jurnal Info Digit (JID), 2024, 2, (1), pp. 246-262
[15] Lina, I.M.: ‘Anticipate password security with burp suite using the brute force attack method’, Jurnal E-Komtek, 2023, 7, (1), pp. 118-127
[16] El Marzak, Y., Chahid, A., Faris, S., and Mansouri, K.: ‘Developing a Unified Cyber Risk Management Framework Using Semantic Technologies and Structured Modeling Approaches’, Engineering, Technology & Applied Science Research, 2026, 16, (1), pp. 31043-31051
[17] Mızrak, F.: ‘Integrating cybersecurity risk management into strategic management: a comprehensive literature review’, Research Journal of Business and Management, 2023, 10, (3), pp. 98-108
[18] Syafitri, W.: ‘Information Security Risk Assessment using NIST 800-30 (Case Study: Academic Information Systes University XYZ) [Penilaian Risiko Keamanan Informasi Menggunakan Metode NIST 800-30 (Studi Kasus: Sistem Informasi Akademik Universitas XYZ)]’, Jurnal CoreIT, 2016, 2, (2), pp. 8-13
[19] Kurniawan, D.K.C., and Sihotang, J.I.: ‘NIST 800-30 Risk Assessment Audit for Academic Excellence: A Roadmap for Strengthening Cybersecurity at Universitas Advent Indonesia’, TeIKa, 2025, 15, (2), pp. 63-77
[20] Prasetyo, B., Salsabila, A., and Retnani, W.E.Y.: ‘IT Risk Management Analysis Based on ISO 31000 and Bow Tie Analysis (BTA) in Higher Education Institution’, Indonesian Journal of Information Systems, 2024, 7, (1), pp. 84-96
[21] Raihan, S.D., Prabowo, S., and Oktaria, D.: ‘Security Vulnerable Evaluation of a Web Application with Vulnerability Assessment and Penetration Testing using OWASP and NIST SP 800-30 Revision 1 [Evaluasi Risiko Celah Keamanan Pada Aplikasi Web Dengan Penilaian Kerentanan dan Pengujian Penetrasi Menggunakan Metode OWASP dan NIST SP 800-30 Revisi 1]’, LOGIC: Jurnal Penelitian Informatika, 2024, 2, (2)
[22] Monageng, T., and Esiefarienrhe, B.M.: ‘Analysis of Risk Assessment Framework Using Agile Methodology and Computer-Aided Software Engineering Tools’, Indonesian Journal of Information Systems, 2026, 8, (2), pp. 157-174
[23] Acharya, S., and Pandya, V.: ‘Bridge between black Box and white Box–gray Box testing technique’, International Journal of Electronics and Computer Science Engineering, 2012, 2, (1), pp. 175-185
[24] Muna, S.R., Santoso, H.B., and Siang, J.J.: ‘Internal Compliance Audit of the Information Security Management System in a Cybersecurity Company based on ISO/IEC 27001’, Sistemasi: Jurnal Sistem Informasi, 2026, 15, (6), pp. 2267-2278
[25] Dewanti, A.C., Santoso, H.B., and Siang, J.J.: ‘ISO 27001 Annex A Compliance Analysis of a Cybersecurity Company [Analisis Kepatuhan ISO 27001 Annex A pada Perusahaan Keamanan Siber]’, Jutisi: Jurnal Ilmiah Teknik Informatika dan Sistem Informasi, 2026, 15, (3), pp. 996-1007
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Indonesian Journal of Information Systems as journal publisher holds copyright of papers published in this journal. Authors transfer the copyright of their journal by filling Copyright Transfer Form and send it to Indonesian Journal of Information Systems.

Indonesian Journal of Information Systems is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.












