Author
Listed:
- Idalia Francisca Viegas
(Ganesha University of Education)
- Kadek Yota Ernanda Aryanto
(Ganesha University of Education)
- I Ketut Resika Arthana
(Ganesha University of Education)
Abstract
This study presents mini penetration testing assessment conducted on the Human Resource Management System (HRMS) hosted at https://hrms.tic.gov.tl . This assessment aims to evaluate the security level of the system by considering the aspects of Confidentiality, Integrity, and Availability (CIA) through several processes, including reconnaissance, vulnerability scanning, and security configuration analysis. The assessment process was conducted using various automated security tools such as Nuclei, Nmap, Subfinder, and Acunetix to identify potential security weaknesses within the web application environment. The testing activities were conducted on November 2025 using passive and semi-active approaches without exploitation activities, in accordance with ethical considerations, organizational authorization, and operational security boundaries. The assessment identified several Low and Informational findings related to missing security headers, insecure cookie configurations, and weak client-side security settings. Although no High or Critical vulnerabilities were identified, the findings should not be interpreted as evidence that the system is fully secure because the assessment scope did not include exploitation or internal infrastructure testing. The results indicate that additional hardening, preventive controls, and continuous security governance mechanisms are still necessary to strengthen the overall security posture of the HRMS environment. Recommendations based on ISO/IEC 27001, Zero Trust principles, and Web Application Firewall protection are proposed to improve organizational cybersecurity resilience.
Suggested Citation
Idalia Francisca Viegas & Kadek Yota Ernanda Aryanto & I Ketut Resika Arthana, 2026.
"Vulnerabilities assessment of a web-based human resources management system using a penetration testing approach (hrms.tic.gov.tl),"
Priviet Social Sciences Journal, Privietlab Research Center, vol. 6(5), pages 411-424, May.
Handle:
RePEc:prv:pssjpv:1801
DOI: 10.55942/pssj.v6i5.1801
Download full text from publisher
Corrections
All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:prv:pssjpv:1801. See general information about how to correct material in RePEc.
If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.
We have no bibliographic references for this item. You can help adding them by using this form .
If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.
For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: Mochammad Fahlevi (email available below). General contact details of provider: https://journal.privietlab.org/index.php/PSSJ .
Please note that corrections may take a couple of weeks to filter through
the various RePEc services.