Skip to main navigation menu Skip to main content Skip to site footer

Articles

Vol. 10 No. 7 (2025): Kohesi: Jurnal Sains dan Teknologi, ISSN 3025-1311

INTEGRASI KEAMANAN API BERBASIS RBAC DAN AUDIT TRAIL PADA BACKEND SISTEM INFORMASI EKSEKUTIF REKRUTMEN UNTUK OPTIMALISASI PENGAMBILAN KEPUTUSAN STRATEGIS (STUDI KASUS: PT SOLOMON INDO GLOBAL)

Submitted
December 30, 2025
Published
2025-12-31

Abstract

Backend development for recruitment Executive Information Systems (SIE) faces the challenge of aligning fast statistical data presentation (low latency) with strict protection of sensitive data. This research aims to design a REST API architecture using NestJS and PostgreSQL which focuses on two main pillars. First, to support executive needs in making strategic decisions, optimization of data aggregation at the database level (database-level aggregation) is carried out. This enables responsive presentation of statistical metrics and drill-down visualization features without burdening server memory. Second, implementing layered security (Defense in Depth) through JWT authentication, role-based authorization (Role-Based Access Control/RBAC), and Bcrypt hashing. In addition, an Audit Trail mechanism is implemented on the history table to ensure accountability and the principle of Non-Repudiation. Test results show that this architecture is successful in providing accurate and fast SIE data, while mitigating the risk of illegal access and data manipulation through strict access controls.

References

  1. Sahyudi, M., & Susanto, E. R. (2025). Analisis Implementasi Sistem Keamanan Basis Data Berbasis Role-Based Access Control (RBAC) pada Aplikasi Enterprise Resource Planning. SATESI: Jurnal Sains Teknologi dan Sistem Informasi, 5(1), 105-116.
  2. Gamayanto, I., Kurniawan, M. C., & Sanyoto, G. K. (2025). Security Evaluation of Keycloak-Based Role-Based Access Control in Microservice Architectures Using the OWASP ASVS Framework. Journal of Applied Informatics and Computing, 9(6), 3964-3973.
  3. Yuricha, Y., & Phan, I. K. (2023). Penerapan Role Based Access Control dalam Sistem Supply Chain Management Berbasis Cloud: The Implementation of Role Based Access Control in a Cloud-Based Supply Chain Management System. MALCOM: Indonesian Journal of Machine Learning and Computer Science, 3(2), 339-348.
  4. ARAVINDA, A. K., & Divya, T. L. (2024). Security measures implemented in RESTful API Development. OPEN ACCESS RESEARCH JOURNAL OF ENGINEERING AND TECHNOLOGY Учредители: Open Access Research Journals Publication, 7(1), 105-112.
  5. Tanveer, F., Iradat, F., Iqbal, W., & Ahmad, A. (2025). Towards Secure APIs: A Survey on RESTful API Vulnerability Detection. Computers, Materials & Continua, 84(3).
  6. Ojha, P. R. (2024). Securing the digital frontier: Best practices for RESTful API protection in modern web applications. International Journal of Engineering Trends and Technology Research (IJETR), 9(2), 481–491. https://doi.org/10.5281/zenodo.13860934
  7. Ferdian, F., Fransen, L. A., & Hermawan, H. (2024). Rancang Bangun Sistem Informasi Kepegawaian Berbasis Website Pada PT. XYZ. MSC (MDP Student Conference), 3(1), 917–925.
  8. Putra, I. N. D. P., Astawa, I. G. S., & Mogi, I. K. A. (2024). Aplikasi Manajemen Karyawan Berbasis Website Sebagai Pengelola Karyawan di CV Tridatu Solution. Jurnal Pengabdian Informatika, 2(4), 617–622.
  9. Supriyanto, H., Nurhadi, M., Prasetya, M. S., Hermansyah, D., & Puspitaningrum, A. C. (2022). Pembuatan media informasi digital sebagai sarana informasi dan promosi sekolah. JMM (Jurnal Masyarakat Mandiri), 6(5).
  10. Panuntun, R., Rochim, A. F., & Martono, K. T. (2015). Perancangan papan informasi digital berbasis web pada Raspberry Pi. Jurnal Teknologi dan Sistem Komputer, 3(2), 192–197.
  11. Ginting, R. (2020). Kemampuan literasi media pada era informasi digital di kalangan mahasiswa Kota Medan. Talenta Conference Series: Local Wisdom, Social, and Arts (LWSA), 3(1).

Similar Articles

1-10 of 193

You may also start an advanced similarity search for this article.