Network Infrastructure Security Audit at a Vocational School Teaching Factory Using the NIST Cybersecurity Framework
DOI:
https://doi.org/10.29407/intensif.v10i2.28354Keywords:
NIST Cybersecurity Framework, Network Security Audit, Cybersecurity Maturity, Centralized Log Monitoring, Educational Network InfrastructureAbstract
Background: The increasing dependence on public-facing network services exposes educational institutions to growing cybersecurity threats, highlighting the need for structured security evaluations. This study evaluates cybersecurity maturity in a vocational school Teaching Factory (TEFA) environment using the NIST Cybersecurity Framework (NIST CSF) 1.1. Objective: To assess the cybersecurity maturity of the network infrastructure at TEFA TKJ SMK Al-Mufti, determine its implementation tier, and develop practical security improvements. Methods: A qualitative–quantitative descriptive case study was conducted using observations, interviews, questionnaires based on NIST CSF categories and subcategories, and document analysis. Risk assessment followed NIST SP 800-30, while gap analysis compared the Current Profile with a Target Profile defined at Tier 3 across the five NIST CSF core functions. Results: Although questionnaire results produced an average score of 3.45 (Tier 3), qualitative validation indicated that cybersecurity practices remained informal and inconsistently documented, resulting in an actual maturity level of Tier 2 (Risk Informed). A one-level gap was identified across all NIST CSF functions. Key risks included weak authentication, the absence of formal cybersecurity policies, and manual log monitoring. Implementing centralized log monitoring using Graylog improved visibility and strengthened the Detect and Respond functions. Conclusion: NIST CSF effectively identifies cybersecurity gaps and supports targeted improvements in educational network infrastructures. Further research should evaluate the long-term effectiveness of implemented controls and extend assessments to multiple institutions.
Downloads
References
[1] N. O. Miracle, “The Importance Of Network Security In Protecting Sensitive Data And Information,” International Journal Of Research And Innovation In Applied Science, Vol. Ix, No. Vi, Pp. 259–270, 2024, Doi: 10.51584/Ijrias.2024.906024.
[2] Muhammad Rifqi Maulana And Abdul Kholiq, “Analisis Dan Implementasi Keamanan Jaringan Mikrotik Dengan Metode Ip Filtering Dan Port Knockiing ( Studi Kasus Barokah.Net ),” Jurnal Limits, Vol. 19, No. 02, Pp. 71–80, Feb. 2023, Doi: 10.59134/Jlmt.V19i02.199.
[3] F. Panjaitan And A. Aprilo, “Analisis Manajemen Risiko Keamanan Jaringan Menggunakan Framework Nist,” Jurnal Ilmiah Matrik, Vol. 24, No. 1, Pp. 71–81, Apr. 2022, Doi: 10.33557/Jurnalmatrik.V24i1.1682.
[4] E. Handoyo And Izza Eka Nigrum, “Penilaian Risiko Keamanan Siber Kampus Menggunakan Framework Cybersecurity Nist 1.1,” Jurnal Coscitech (Computer Science And Information Technology), Vol. 4, No. 3, Pp. 677–685, Jan. 2024, Doi: 10.37859/Coscitech.V4i3.5628.
[5] R. Windari And Sriyanto, “Tinjauan Implementasi National Institute Of Standards And Technology (Nist) Dalam Meningkatkan Keamanan Jaringan Dengan Cybersecurity Framework (Csf) : Studi Kasus Smkn4 Bandar Lampung,” Jurnal Ilmu Komputer, Sistem Informasi, Teknik Informatika, Vol. 3, No. 1, Pp. 27–40, Mar. 2024.
[6] T. S. Putri, N. M. Mutiah, And D. P. Prawira, “Analisis Manajemen Risiko Keamanan Informasi Menggunakan Nist Cybersecurity Framework Dan Iso/Iec 27001:2013 (Studi Kasus: Badan Pusat Statistik Kalimantan Barat),” Coding Jurnal Komputer Dan Aplikasi, Vol. 10, No. 02, P. 237, Oct. 2022, Doi: 10.26418/Coding.V10i02.54972.
[7] G. González-Granadillo, S. González-Zarzosa, And R. Diaz, “Security Information And Event Management (Siem): Analysis, Trends, And Usage In Critical Infrastructures,” Sensors, Vol. 21, No. 14, P. 4759, Jul. 2021, Doi: 10.3390/S21144759.
[8] A. Ibrahim, C. Valli, I. Mcateer, And J. Chaudhry, “A Security Review Of Local Government Using Nist Csf: A Case Study,” J. Supercomput., Vol. 74, No. 10, Pp. 5171–5186, Oct. 2018, Doi: 10.1007/S11227-018-2479-2.
[9] R. Safarudin, Zulfamanna, M. Kustati, And N. Sepriyanti, “Penelitian Kualitatif,” Innovative: Journal Of Social Science Research, Vol. 3, No. 2, Pp. 9680–9694, 2023.
[10] J. L. Sidel, R. N. Bleibaum, And K. W. C. Tao, “Quantitative Descriptive Analysis,” In Descriptive Analysis In Sensory Evaluation, Wiley, 2018, Pp. 287–318. Doi: 10.1002/9781118991657.Ch8.
[11] M. P. Barrett, “Framework For Improving Critical Infrastructure Cybersecurity, Version 1.1,” Gaithersburg, Md, Apr. 2018. Doi: 10.6028/Nist.Cswp.04162018.
[12] J. L. Salas-Riega, Y. Riega-Virú, M. Ninaquispe-Soto, And J. M. Salas-Riega, “Cybersecurity And The Nist Framework: A Systematic Review Of Its Implementation And Effectiveness Against Cyber Threats,” International Journal Of Advanced Computer Science And Applications, Vol. 16, No. 6, 2025, Doi: 10.14569/Ijacsa.2025.0160672.
[13] Z. Illési, “Digital Evidence Management For Organizational Legal Compliance,” Interdisciplinary Description Of Complex Systems, Vol. 23, No. 3, Pp. 217–229, 2025, Doi: 10.7906/Indecs.23.3.3.
[14] M. Destriani And Y. H. Putra, “Rencana Audit Tata Kelola Sistem Informasi Di Universitas Subang Menggunakan Framework Cobit 2019,” Jurnal Tata Kelola Dan Kerangka Kerja Teknologi Informasi, Vol. 9, No. 1, Pp. 19–33, May 2023, Doi: 10.34010/Jtk3ti.V9i1.9164.
[15] R. Ramadhana, B. V. Izaac, G. W. Tangka, And J. Y. Mambu, “Information Technology Governance Analysis Using The Cobit 2019 Framework At Pt. Daya Adicipta Wisesa,” Jurnal Informasi Dan Teknologi, Pp. 141–146, Nov. 2023, Doi: 10.60083/Jidt.V5i3.414.
[16] M. Fadya And D. N. Utama, “Towards Secure Information Systems: Developing And Implementing An Information Security Evaluation Model Using Nist Csf And Cobit 2019,” Tem Journal, Pp. 182–191, Feb. 2025, Doi: 10.18421/Tem141-17.
[17] R. Ksanjaya And E. T. Rahayu, “Motivasi Siswa Dalam Kegiatan Ekstrakurikuler Futsal Di Sma Negeri 1 Blanakan,” Jurnal Pendidikan Dan Konseling, Vol. 4, No. 5, Pp. 6094–6099, 2022.
[18] Y. Thomas, H. Debar, And B. Morin, “Improving Security Management Through Passive Network Observation,” In First International Conference On Availability, Reliability And Security (Ares’06), Ieee, 2006, Pp. 8 Pp. – 389. Doi: 10.1109/Ares.2006.74.
[19] C. Hove, M. Tarnes, M. B. Line, And K. Bernsmed, “Information Security Incident Management: Identified Practice In Large Organizations,” In 2014 Eighth International Conference On It Security Incident Management & It Forensics, Ieee, May 2014, Pp. 27–46. Doi: 10.1109/Imf.2014.9.
[20] L. Bernardo, S. Malta, And J. Magalhães, “An Evaluation Framework For Cybersecurity Maturity Aligned With The Nist Csf,” Electronics (Basel)., Vol. 14, No. 7, P. 1364, Mar. 2025, Doi: 10.3390/Electronics14071364.
[21] A. Joshi, S. Kale, S. Chandel, And D. Pal, “Likert Scale: Explored And Explained,” Br. J. Appl. Sci. Technol., Vol. 7, No. 4, Pp. 396–403, Jan. 2015, Doi: 10.9734/Bjast/2015/14975.
[22] L.-F. Kwok, P. P. K. Fung, And D. Longley, “Security Documentation,” In Advances In Information Security Management & Small Systems Security, Boston, Ma: Springer Us, 2001, Pp. 127–139. Doi: 10.1007/0-306-47007-1_10.
[23] T. S. Ardan, D. F. Zahra, F. R. Junaedi, And S. R. Widianto, “Dokumentasi Software Testing Berstandar Ieee 829-2008 Untuk Learning Management System Fakultas Ilmu Komputer Universitas Subang,” Jurnal Multinetics, Vol. 6, No. 2, Pp. 179–191, Jan. 2020, [Online]. Available: Www.Publishing.Gramediana.Com.
[24] C. Schmitz, M. Schmid, D. Harborth, And S. Pape, “Maturity Level Assessments Of Information Security Controls: An Empirical Analysis Of Practitioners Assessment Capabilities,” Comput. Secur., Vol. 108, P. 102306, Sep. 2021, Doi: 10.1016/J.Cose.2021.102306.
[25] I. Kusmaryono, D. Wijayanti, And H. R. Maharani, “Number Of Response Options, Reliability, Validity, And Potential Bias In The Use Of The Likert Scale Education And Social Science Research: A Literature Review,” Int. J. Educ. Method., Vol. 8, No. 4, Pp. 625–637, Nov. 2022, Doi: 10.12973/Ijem.8.4.625.
[26] M. Al Fikri, F. A. Putra, Y. Suryanto, And K. Ramli, “Risk Assessment Using Nist Sp 800-30 Revision 1 And Iso 27005 Combination Technique In Profit-Based Organization: Case Study Of Zzz Information System Application In Abc Agency,” Procedia Comput. Sci., Vol. 161, Pp. 1206–1215, 2019, Doi: 10.1016/J.Procs.2019.11.234.
[27] I. D. Sánchez-García, J. Mejía, And T. San Feliu Gilabert, “Cybersecurity Risk Assessment: A Systematic Mapping Review, Proposal, And Validation,” Applied Sciences, Vol. 13, No. 1, P. 395, Dec. 2022, Doi: 10.3390/App13010395.
[28] F. N. Sitorus And R. Harwahyu, “Analysis Of Employee Capacity Gap In Managing Network Security And Its Implementation Towards Insider Threat Prevention,” Malcom: Indonesian Journal Of Machine Learning And Computer Science, Vol. 5, No. 2, Pp. 635–644, Apr. 2025, Doi: 10.57152/Malcom.V5i2.1878.
[29] National Institute Of Standards And Technology, “The Nist Cybersecurity Framework (Csf) 2.0,” Feb. 2024. Doi: 10.6028/Nist.Cswp.29.
[30] N. Chaiwut And W. Rueangsirarak, “M-Ses: An Online Cybersecurity Self-Evaluation System To Mitigate The Risk Of Cybersecurity Attacks In Thailand,” Science, Engineering And Health Studies, P. 25020008, Dec. 2025, Doi: 10.69598/Sehs.19.25020008.
[31] M. N. Y. Marican, S. A. Razak, A. Selamat, And S. H. Othman, “Cyber Security Maturity Assessment Framework For Technology Startups: A Systematic Literature Review,” Ieee Access, Vol. 11, Pp. 5442–5452, 2023, Doi: 10.1109/Access.2022.3229766.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Maya Destriani, Bintang Najarul Haq Mulyadi, Tazkia Salsabila Ardan

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors who publish with this journal agree to the following terms:
- Copyright on any article is retained by the author(s).
- The author grants the journal, the right of first publication with the work simultaneously licensed under a Creative Commons Attribution License that allows others to share the work with an acknowledgment of the work’s authorship and initial publication in this journal.
- Authors are able to enter into separate, additional contractual arrangements for the non-exclusive distribution of the journal’s published version of the work (e.g., post it to an institutional repository or publish it in a book), with an acknowledgment of its initial publication in this journal.
- Authors are permitted and encouraged to post their work online (e.g., in institutional repositories or on their website) prior to and during the submission process, as it can lead to productive exchanges, as well as earlier and greater citation of published work.
- The article and any associated published material is distributed under the Creative Commons Attribution-ShareAlike 4.0 International License


