CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
🌙☀️
Log inStart free
Home/Templates/Cybersecurity

🔐 Cybersecurity · C4 Architecture · Pro

Security Operations Centre Architecture

A SOC platform: logs and alerts flow into a SIEM, SOAR playbooks automate response, and analysts work cases.

More Cybersecurity templates

C4 Architecture diagrams are part of Pro. Anyone can view this one; generating and editing it needs Pro.

Drawing diagram…

What this diagram shows

  • EDR, firewall and cloud logs all land in the SIEM
  • SOAR playbooks handle routine alerts automatically
  • Threat intelligence enriches every alert

Prompt used

Security operations centre architecture: log sources (EDR agents, firewalls, cloud audit logs, identity provider) send data to a log collector and the SIEM (Microsoft Sentinel / Splunk). Detection rules raise alerts; a SOAR platform runs playbooks (enrich with threat intelligence, isolate host via EDR, disable user in the IdP). Analysts investigate in a case management tool and escalate incidents.

Mermaid code
C4Container
title Security Operations Centre
Person(analyst, "SOC Analyst", "Investigates alerts")
System_Ext(edr, "EDR Agents", "Endpoint telemetry")
System_Ext(fw, "Firewalls and Proxies", "Network logs")
System_Ext(cloud, "Cloud Audit Logs", "AWS, Azure, M365")
System_Ext(idp, "Identity Provider", "Sign-in logs")
System_Ext(ti, "Threat Intelligence Feeds", "IOCs")
System_Boundary(soc, "SOC Platform") {
  Container(collector, "Log Collector", "Syslog / agents", "Normalises logs")
  Container(siem, "SIEM", "Microsoft Sentinel", "Detection rules")
  Container(soar, "SOAR", "Playbooks", "Automated response")
  Container(cases, "Case Management", "Web app", "Incidents and evidence")
}
Rel(edr, collector, "Telemetry")
Rel(fw, collector, "Logs")
Rel(cloud, collector, "Audit logs")
Rel(idp, collector, "Sign-ins")
Rel(collector, siem, "Normalised events")
Rel(siem, soar, "Alerts")
Rel(ti, soar, "Enrichment")
Rel(soar, edr, "Isolate host")
Rel(soar, idp, "Disable user")
Rel(soar, cases, "Creates case")
Rel(analyst, cases, "Investigates")

Related templates

C4 ArchitectureProCybersecurity

Zero Trust Architecture

A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.

FlowchartCybersecurity

Security Incident Response Workflow

A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.

Data FlowCybersecurity

SIEM Log Pipeline

How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.

SequenceCybersecurity

SAML Single Sign-On Login

How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.

NetworkCybersecurity

DMZ Network Architecture

A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.

MindmapCybersecurity

Threat Model Mindmap (STRIDE)

A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.