Information System Security Analysis at RKSchool Depok Using Penetration Testing and Vulnerability Assessment Methods

  • Ardika Oktavian Sekolah Tinggi Teknologi Terpadu Nurul Fikri
  • Zaki Imaduddin Sekolah Tinggi Teknologi Terpadu Nurul Fikri

Abstract

This study aims to evaluate the security level of the information system used by RKSchool, a micro-scale educational institution that relies on digital platforms for daily operations. The increasing number of cyberattacks targeting the education and MSME sectors highlights the need for systematic security assessments to minimize risks related to personal data exposure and service disruption. This research integrates penetration testing and vulnerability assessment based on the OWASP Web Security Testing Guide with perception analysis using the Technology Acceptance Model to examine organizational readiness in adopting the recommended security controls. The assessment was conducted through five main phases, including reconnaissance, scanning, exploitation, post-exploitation, and reporting. The findings indicate several vulnerabilities in server configuration, such as missing security headers, the absence of CSRF protection, and the lack of a Content Security Policy. TAM analysis shows that perceived usefulness and perceived ease of use have not yet formed a consistent behavioral intention toward security practices. The integration of both technical and behavioral findings demonstrates that the major risks do not solely originate from system weaknesses but also from limited organizational preparedness in implementing comprehensive security measures.

Downloads

Download data is not yet available.

References

M. T. Rusydi, Cyber Law Policy Development: Indonesias Response to International Cybercrime Threats, J. Progress. Law Leg. Stud., vol. 3, no. 01, pp. 6985, 2025, doi: 10.59653/jplls.v3i01.1365.

S. A. Putra, M. Lubis, and R. R. Saedudin, In Deep Security Management Strategy: Vulnerability Assessment Within Educational Institution, vol. 1, no. 1. Association for Computing Machinery, 2023. doi: 10.1145/3592307.3592326.

Owasp Foundation, Owasp Top Ten 2025, owasp.org. Accessed: Oct. 20, 2025. [Online]. Available: https://owasp.org/www-project-top-ten/

M. R. Syailendra, G. Lie, and A. Sudiro, Personal Data Protection Law In Indonesia: Challenges And Opportunities, Indones. Law Rev., vol. 14, no. 2, pp. 5672, 2024, [Online]. Available: https://scholarhub.ui.ac.id/ilrev/vol14/iss2/4

D. Supriadi, E. Suryadi, R. Muslim, and L. Delsi Samsumar, Implementasi Vulnerability Assessment Owasp (Open Web Application Security Project) Pada Website Universitas Teknologi Mataram, J. Data Anal. Information, Comput. Sci., vol. 1, no. 4, Oct. 2024.

S. Anshori Robbani, Analisis Kerentanan Keamanan Aplikasi Manajemen Aset Berbasis Web Menggunakan Metode OWASP ( Open Web Application Security Project ) Studi Kasus PT. XYZ, Sekolah Tinggi Teknologi Terpadu Nurul Fikri, Jakarta, 2021.

F. C. Islami, Analisis Kerentanan Website XYZ Menggunakan Metode Vulnerability Assessment Penetration Testing Dan OWASP WSTG (Studi Kasus: XYZ), J. Apl. dan Teor. Ilmu Komput., vol. 7, no. 2, pp. 9399, 2025, doi: 10.17509/jatikom.v7i2.80934.

N. Nursyabani, Analisis Keamanan Website Kota Depok Menggunakan Metode Vulnerability Assessment, Politeknik Negeri Jakarta, 2023. [Online]. Available: https://repository.pnj.ac.id/id/eprint/12103/

I. Naufaldi, Pengaruh Perceived Ease Of Use , Perceived Usefulness , dan Trust terhadap Intention To Use, J. Manajerial dan Kewirausahaan, vol. II, no. 3, pp. 715722, 2020.

Owasp Foundation, OWASP Web Security Testing Guide, owasp.org. Accessed: Oct. 20, 2025. [Online]. Available: https://owasp.org/www-project-web-security-testing-guide/

E. Liyanto, Analisis Penerapan Sistem Manajemen Keamanan Informasi Pada Website Official STT NF Dengan SNI ISO/IEC 27001:2022, Sekolah Tinggi Teknologi Terpadu Nurul FIkri, Jakarta, 2024. [Online]. Available: https://repository.nurulfikri.ac.id/id/eprint/585/1/2024-Epri Liyanto-Sistem Informasi-Fulltext - Epri Liyanto.pdf

J. N. Goel and B. M. Mehtre, Vulnerability Assessment & Penetration Testing as a Cyber Defence Technology, Procedia Comput. Sci., vol. 57, pp. 710715, 2015, doi: 10.1016/j.procs.2015.07.458.

H. Afifah, T. Ibrahim, and O. Arifudin, Implementasi Technology Acceptance Model (Tam) Pada Penerimaan Aplikasi Sistem Manajemen Pendidikan Di Lingkungan Madrasah, J. Tahsinia, vol. 5, no. 9, pp. 13531369, 2024, [Online]. Available: https://jurnal.rakeyansantang.ac.id/tahsinia/article/view/665

M. Alhamed and M. M. H. Rahman, A Systematic Literature Review on Penetration Testing in Networks: Future Research Directions, Appl. Sci., vol. 13, no. 12, 2023, doi: 10.3390/app13126986.

A. A. Dianaris, E. Pramana, and H. Budianto, Faktor-Faktor yang Mempengaruhi Adopsi E-learning untuk Siswa SMA di Indonesia dengan Menggunakan Extended Technology Acceptance Model, J. Inf. Syst. Hosp. Technol., vol. 4, no. 01, pp. 1326, Mar. 2022, doi: 10.37823/insight.v4i01.179.

C. A. Sulistyo, G. Firmansyah, B. Tjahjono, and A. M. Widodo, Analysis of The Maturity Level of Cyber Security in The Context of Personal Data Protection for MSMEs in Depok City, Eduvest - J. Univers. Stud., vol. 5, no. 2, pp. 21552171, 2025, doi: 10.59188/eduvest.v5i2.50822.

S. Supangat, A. R. Amna, and M. Y. F. Rochman, Penetration Testing and Vulnerability Analysis of SINTA Platform to Strengthen Privacy and Data Protection, J. Inf. Technol. Cyber Secur., vol. 3, no. 2, pp. 7983, 2025, doi: 10.30996/jitcs.12216.

S. Nurmuhsina, Nuranisah, M. Hasnaa Syamila, M. Sayyid Ramadhan, and T. Nabarian, Analisis Faktor Yang Memengaruhi Adopsi Aplikasi No Thanks Dalam Mendukung Gerakan Bds Terhadap Israel, J. Inform. Terpadu, vol. 11, no. 1, pp. 2936, 2025, [Online]. Available: https://journal.nurulfikri.ac.id/index.php/JIT

R. Diana, I. V. Paputungan, and A. Luthfi, Integration of TAM and DeLone and McLean Models to Evaluate the Quality of NAMPAH Applications, J. Teknol. Dan Sist. Inf. Bisnis, vol. 6, no. 4, pp. 723731, 2024, doi: 10.47233/jteksis.v6i4.1583.

Haeruddin, Gautama Wijaya, H. Winata, Sukma Aji, and Muhammad Nur Faiz, Website Security Analysis Using Vulnerability Assessment Method, J. Innov. Inf. Technol. Appl., vol. 6, no. 2, pp. 173180, 2024, doi: 10.35970/jinita.v6i2.2476.

Alfian, M. Purwaningsing, and F. D. Nugroho Wicaksono, Pencegahan Kerentanan Keamanan Jaringan Komputer Mikrotik Menggunakan Metode Penetration Testing, J. Ilm. FIFO, Nov. 2024.

W. Lazarov, P. Seda, Z. Martinasek, and R. Kummel, Penterep: Comprehensive penetration testing with adaptable interactive checklists, Comput. Secur., vol. 154, no. March, p. 104399, 2025, doi: 10.1016/j.cose.2025.104399.

N. Mamuriyah, S. E. Prasetyo, and A. O. Sijabat, Rancangan Sistem Keamanan Jaringan dari serangan DDoS Menggunakan Metode Pengujian Penetrasi, J. Teknol. Dan Sist. Inf. Bisnis, vol. 6, no. 1, pp. 162167, 2024, doi: 10.47233/jteksis.v6i1.1124.

M. Maleno and A. Kusumawati, Comparative Analysis of Indonesias Personal Data Protection Law with the European Union and California Regulations to Identify Best Practices in Protecting Public Privacy Rights, Indones. Law Collage Assoc. Law J. (ILCA Law Journal), vol. 3, 2024.

I. D. Snchez-Garca, J. Meja, and T. San Feliu Gilabert, Cybersecurity Risk Assessment: A Systematic Mapping Review, Proposal, and Validation, Appl. Sci., vol. 13, no. 1, 2023, doi: 10.3390/app13010395.

DLA Piper, Data Protection Laws of the World, 2025. [Online]. Available: https://www.dlapiperdataprotection.com/

Ministry of Communication and Informatics Indonesia, Govt: Law on Personal Data Protection Provides Legal Protection, en.mkri.id. Accessed: Oct. 20, 2025. [Online]. Available: https://en.mkri.id/news/details/2023-02-13/Govt:_Law_on_Personal_Data_Protection_Provides_Legal_Protection

M. Albahar, D. Alansari, and A. Jurcut, An Empirical Comparison of Pen-Testing Tools for Detecting Web App Vulnerabilities, Electron., vol. 11, no. 19, Oct. 2022, doi: 10.3390/electronics11192991.

C. N. Siahaan, M. Rufisanto, R. Nolasco, S. Achmad, and C. R. P. Siahaan, Study of Cross-Site Request Forgery on Web-Based Application: Exploitations and Preventions, in Procedia Computer Science, Elsevier B.V., 2023, pp. 92100. doi: 10.1016/j.procs.2023.10.506.

I. F. Ashari, V. Oktarina, R. G. Sadewo, and S. Damanhuri, Analysis of Cross Site Request Forgery (CSRF) Attacks on West Lampung Regency Websites Using OWASP ZAP Tools, J. Sisfokom (Sistem Inf. dan Komputer), vol. 11, no. 2, pp. 276281, Aug. 2022, doi: 10.32736/sisfokom.v11i2.1393.

N. Albalawi, N. Alamrani, R. Aloufi, M. Albalawi, A. Aljaedi, and A. R. Alharbi, The Reality of Internet Infrastructure and Services Defacement: A Second Look at Characterizing Web-Based Vulnerabilities, Electron., vol. 12, no. 12, Jun. 2023, doi: 10.3390/electronics12122664.

G. B. Thenu and C. Rudianto, Audit Sistem Informasi Menggunakan Framework Cobit 2019 (Studi Kasus: PT X), J. Teknol. Dan Sist. Inf. Bisnis, vol. 6, no. 4, pp. 762767, 2024, doi: 10.47233/jteksis.v6i4.1601.

Published
2026-01-26
How to Cite
Oktavian, A., & Imaduddin, Z. (2026). Information System Security Analysis at RKSchool Depok Using Penetration Testing and Vulnerability Assessment Methods. Jurnal Teknologi Dan Sistem Informasi Bisnis, 8(1), 46-54. https://doi.org/10.47233/jteksis.v8i1.2363
Section
Articles