DESIGNING A THREAT MODELING-DRIVEN RISK MANAGEMENT FRAMEWORK FOR SECURING PT XYZ’S MEDIA CONTENT MANAGEMENT SYSTEM

dc.contributor.authorMalun, Nicholaus Ola
dc.contributor.authorLim, Charles
dc.contributor.authorSilaen, Kalpin Erlangga
dc.date.accessioned2026-04-27T07:57:25Z
dc.date.issued2025-08-12
dc.description.abstractThis thesis aims to design a threat modelling driven risk management framework to enhance the security of PT XYZ's Content Management System (CMS), which is critical for safeguarding digital assets and ensuring the integrity of media operations. The research employs a combination of STRIDE and LINDDUN methodologies to systematically identify and classify both security and privacy threats across CMS components. Each identified threat is evaluated using the DREAD scoring model to prioritize risks based on their potential impact, reproducibility, exploitability, affected users, and discoverability. The study also conducts a comprehensive vulnerability analysis and security gap assessment to uncover weaknesses aligned with common threat vectors, including those reflected in the OWASP Top 10. Based on these findings, the research proposes a set of mitigation strategies and security controls aligned with ISO/IEC 27001:2022 to ensure both technical and organizational resilience. The findings reveal that PT XYZ’s CMS faces critical risks such as credential reuse, token replay attacks, and unauthorized API access, which require immediate mitigation. The practical implication of this thesis is the development of a tailored risk management model that integrates threat modeling into the software development lifecycle (SDLC), enabling PT XYZ to adopt a proactive and structured approach to CMS security.
dc.identifier.urihttps://dspace-repository.sgu.ac.id/handle/123456789/82
dc.language.isoen
dc.publisherSwiss German University
dc.subjectCMS
dc.subjectSTRIDE
dc.subjectLINDDUN
dc.subjectDREAD ISO 27001:2022
dc.subjectOWASP Top 10
dc.titleDESIGNING A THREAT MODELING-DRIVEN RISK MANAGEMENT FRAMEWORK FOR SECURING PT XYZ’S MEDIA CONTENT MANAGEMENT SYSTEM
dc.typeThesis

Files

Original bundle

Now showing 1 - 5 of 6
Loading...
Thumbnail Image
Name:
COVER.pdf
Size:
253.66 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
CHAPTER 1.pdf
Size:
416.07 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
CHAPTER 2.pdf
Size:
1019.23 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
CHAPTER 3.pdf
Size:
622.45 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
CHAPTER 4.pdf
Size:
984.14 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed to upon submission
Description:

Collections