
π Cybersecurity Β· State Machine
The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.
Drawing diagramβ¦
Vulnerability management state machine: a scanner discovers a vulnerability (open). Security triages it with CVSS and asset criticality; false positives are closed. Real findings are assigned to the owning team with an SLA. The team patches or mitigates; a re-scan verifies the fix before closing. If it cannot be fixed, the owner can request risk acceptance with an expiry date, after which it is reopened. Missed SLAs escalate.
stateDiagram-v2 [*] --> Open: scanner finding Open --> Triaged: CVSS and asset criticality Triaged --> FalsePositive: not applicable Triaged --> Assigned: owner and SLA set Assigned --> InRemediation InRemediation --> PendingVerification: patch applied PendingVerification --> Closed: re-scan clean PendingVerification --> InRemediation: still vulnerable Assigned --> Escalated: SLA missed Escalated --> InRemediation Assigned --> RiskAccepted: approved exception RiskAccepted --> Open: exception expired FalsePositive --> [*] Closed --> [*]
A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.