
🔐 Cybersecurity · C4 Architecture · Pro
A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.
C4 Architecture diagrams are part of Pro. Anyone can view this one; generating and editing it needs Pro.
Drawing diagram…
Zero trust architecture: employees on laptops reach internal apps only through an identity-aware access proxy. The proxy asks a policy engine, which checks the identity provider (SSO with MFA) and the device management system (disk encryption, patches, EDR running). Allowed requests are forwarded over a private connector to internal apps; every decision is logged to the SIEM. There is no VPN or trusted office network.
C4Container
title Zero Trust Access
Person(employee, "Employee", "Office or remote")
System_Boundary(zt, "Zero Trust Access Layer") {
Container(proxy, "Access Proxy", "Identity-aware proxy", "Every request enters here")
Container(pe, "Policy Engine", "OPA", "Allow or deny per request")
Container(conn, "App Connector", "Private tunnel", "Reaches internal apps")
}
System_Ext(idp, "Identity Provider", "SSO with MFA")
System_Ext(mdm, "Device Management", "Posture: encryption, patches, EDR")
System_Ext(apps, "Internal Apps", "HR, finance, code repos")
System_Ext(siem, "SIEM", "Security logs and alerts")
Rel(employee, proxy, "Requests app", "HTTPS")
Rel(proxy, idp, "Authenticates user")
Rel(proxy, pe, "Asks decision")
Rel(pe, mdm, "Checks device")
Rel(proxy, conn, "Forwards if allowed")
Rel(conn, apps, "Connects")
Rel(pe, siem, "Logs decisions")A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.
How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.
How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.
A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.
A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.
The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.