CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
πŸŒ™β˜€οΈ
Log inStart free
Home/Templates/Cybersecurity

πŸ” Cybersecurity Β· State Machine

Vulnerability Management Lifecycle

The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.

More Cybersecurity templates

Drawing diagram…

What this diagram shows

  • Every finding is triaged against asset criticality
  • Fixes are verified by a re-scan before closing
  • Risk acceptance needs an owner and an expiry date

Prompt used

Vulnerability management state machine: a scanner discovers a vulnerability (open). Security triages it with CVSS and asset criticality; false positives are closed. Real findings are assigned to the owning team with an SLA. The team patches or mitigates; a re-scan verifies the fix before closing. If it cannot be fixed, the owner can request risk acceptance with an expiry date, after which it is reopened. Missed SLAs escalate.

Mermaid code
stateDiagram-v2
  [*] --> Open: scanner finding
  Open --> Triaged: CVSS and asset criticality
  Triaged --> FalsePositive: not applicable
  Triaged --> Assigned: owner and SLA set
  Assigned --> InRemediation
  InRemediation --> PendingVerification: patch applied
  PendingVerification --> Closed: re-scan clean
  PendingVerification --> InRemediation: still vulnerable
  Assigned --> Escalated: SLA missed
  Escalated --> InRemediation
  Assigned --> RiskAccepted: approved exception
  RiskAccepted --> Open: exception expired
  FalsePositive --> [*]
  Closed --> [*]

Related templates

C4 ArchitectureProCybersecurity

Zero Trust Architecture

A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.

FlowchartCybersecurity

Security Incident Response Workflow

A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.

Data FlowCybersecurity

SIEM Log Pipeline

How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.

SequenceCybersecurity

SAML Single Sign-On Login

How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.

NetworkCybersecurity

DMZ Network Architecture

A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.

MindmapCybersecurity

Threat Model Mindmap (STRIDE)

A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.