Security Testing of Personnel Management Information System (SIMPEG) Website Using the OWASP Web Security Testing (WSTG) Framework

Abrar Khalida, 190212028 (2025) Security Testing of Personnel Management Information System (SIMPEG) Website Using the OWASP Web Security Testing (WSTG) Framework. Jurnal Indonesia Sosial Sains, 6 (4). pp. 1-6. ISSN 2723–6692

[thumbnail of menganalisa tentang keamanan website] Text (menganalisa tentang keamanan website)
View of Security Testing of Personnel Management Information System (SIMPEG).pdf - Published Version
Available under License Creative Commons Attribution.

Download (1MB)

Abstract

This research examines the security of the Employee Management Information System (SIMPEG) at UIN Ar-Raniry Banda Aceh using the OWASP Web Security Testing Guide (WSTG) framework. The aim of this study is to identify and address potential security vulnerabilities within the system. The research is divided into three phases: identifying the issues, performing grey-box penetration testing with a focus on client-side testing as outlined in OWASP WSTG, and reporting the findings using the WSTG Checklist. The testing results revealed that out of the thirteen tests conducted, one vulnerability related to Cross Origin Resource Sharing (CORS) was discovered. This study concludes that the SIMPEG system at UIN Ar-Raniry Banda Aceh demonstrates a good level of security, though further improvements are necessary to address the identified issues. Recommendations for enhancing the security of SIMPEG include continuous testing and updates to address emerging threats.

Item Type: Article
Subjects: 000 Computer Science, Information and System
Divisions: Fakultas Tarbiyah dan Keguruan > S1 Pendidikan Teknologi Informasi
Depositing User: Abrar Khalida
Date Deposited: 19 May 2025 03:07
Last Modified: 19 May 2025 03:08
URI: http://repository.ar-raniry.ac.id/id/eprint/45590

Actions (login required)

View Item
View Item