OPTIMALISASI SISTEM INFORMASI PELAYANAN PUBLIK GUNA MENINGKATKAN KEAMANAN INFORMASI DALAM RANGKA MENDUKUNG TUGAS AKADEMI ANGKATAN UDARA
Kata Kunci:
Vital Information Infrastructure, Information Security, Air Force Academy, Cyber Threats, Six Ware Cybersecurity Framework, Penetration Testing, Web Defacement, Human Resources, Facilities, Budgetware, CSIRTAbstrak
Vital Information Infrastructure (VII) in the web-based public service information system at the Air Force Academy (AAU) is very important, but vulnerable to cyber threats. The web defacement incident with online gambling malware infiltration on the aau.ac.id domain is real evidence, damaging the image and credibility of AAU. The main problems at AAU include poor system management, minimal human resource capabilities, and limited facilities. This study aims to analyze and optimize the system to improve information security and identify risks. Using qualitative descriptive analysis methods, a systems approach and the Six Ware Cybersecurity Framework (SWCSF), data were collected through literature studies, interviews, and black box security testing based on NIST SP 800-115. The results of the study identified significant weaknesses in IIV management, including limited human resources (number, training, awareness) and facilities (outdated devices, backup, encryption, monitoring, DRP is not optimal). Security testing found medium and low-level vulnerabilities; WAF managed to ward off some attacks, but directory listing vulnerabilities were found. Comprehensive strategy is recommended: infrastructure modernization, human resource development (training, certification, establishment of CSIRT according to RFC 2350), cooperation (Satsiber Dispamsanau, BSSN), routine audits, and layered security technology with adequate budget support (budgetware). Optimization of IIV in AAU is crucial for operational continuity, protection of vital assets, and support of national strategic interests, making cybersecurity in the military education environment a top priority.
Referensi
[1] Chappell, L. (2019) Wireshark Network Analysis. 2nd ed. San Jose: Protocol Analysis Institute.
[2] Creswell, J.W. & Poth, C.N. (2018) Qualitative Inquiry and Research Design: Choosing Among Five Approaches. 4th ed. Thousand Oaks: SAGE Publications.
[3] Gultom, Y.C. et al. (2018) ‘Six Ware Cyber Security Framework (SWCSF) for security services on critical information infrastructure of military organization’, International Journal of Electrical and Computer Engineering, 8(5), pp. 3490–3499.
[4] Gultom, Y.C. et al. (2021) Six Ware Cyber Security Framework: A Practical Guide for Military Infrastructure. Yogyakarta: Deepublish.
[5] Lyon, G.F. (2009) Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning. San Francisco: Insecure.com LLC.
[6] National Institute of Standards and Technology (NIST) (2008) Technical Guide to Information Security Testing and Assessment. SP 800-115. Gaithersburg: NIST.
[7] Van Rossum, G. & Drake, F.L. (2020) Python 3 Reference Manual. Scotts Valley: CreateSpace.
[8] Whitman, M.E. & Mattord, H.J. (2011) Principles of Information Security. 4th ed. Boston: Cengage Learning.
[9] Whitman, M.E. & Mattord, H.J. (2022) Management of Information Security. 7th ed. Boston: Cengage Learning.

