
π Cybersecurity Β· Database ERD
Tables for an asset inventory and risk register: assets, owners, vulnerabilities, risks, controls and exceptions.
Drawing diagramβ¦
Security risk register database: assets (servers, applications, data stores) have an owner and criticality; vulnerabilities are found on assets; risks describe threats to assets with likelihood and impact; controls mitigate risks through a many-to-many link; exceptions record accepted risks with approver and expiry.
erDiagram
OWNER ||--o{ ASSET : owns
ASSET ||--o{ VULNERABILITY : "found on"
ASSET ||--o{ RISK_ASSET : "exposed in"
RISK ||--|{ RISK_ASSET : affects
RISK ||--o{ RISK_CONTROL : "mitigated by"
CONTROL ||--o{ RISK_CONTROL : mitigates
RISK ||--o{ EXCEPTION : "accepted via"
OWNER {
int id PK
string name
string team
}
ASSET {
int id PK
int owner_id FK
string name
string type
string criticality
}
VULNERABILITY {
int id PK
int asset_id FK
string cve_id
decimal cvss
string status
}
RISK {
int id PK
string title
int likelihood
int impact
}
RISK_ASSET {
int risk_id PK, FK
int asset_id PK, FK
}
CONTROL {
int id PK
string framework_ref
string description
}
RISK_CONTROL {
int risk_id PK, FK
int control_id PK, FK
}
EXCEPTION {
int id PK
int risk_id FK
string approver
date expires_on
}A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.