CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
🌙☀️
Log inStart free
Home/Templates/Cybersecurity

🔐 Cybersecurity · C4 Architecture · Pro

Zero Trust Architecture

A zero trust access model: every request to an internal app is checked for user identity, device health and policy, whether it comes from the office or home.

More Cybersecurity templates

C4 Architecture diagrams are part of Pro. Anyone can view this one; generating and editing it needs Pro.

Drawing diagram…

What this diagram shows

  • No trusted internal network: all access goes through the access proxy
  • Identity provider with MFA plus device posture checks
  • Policy engine decides per request and logs everything to the SIEM

Prompt used

Zero trust architecture: employees on laptops reach internal apps only through an identity-aware access proxy. The proxy asks a policy engine, which checks the identity provider (SSO with MFA) and the device management system (disk encryption, patches, EDR running). Allowed requests are forwarded over a private connector to internal apps; every decision is logged to the SIEM. There is no VPN or trusted office network.

Mermaid code
C4Container
title Zero Trust Access
Person(employee, "Employee", "Office or remote")
System_Boundary(zt, "Zero Trust Access Layer") {
  Container(proxy, "Access Proxy", "Identity-aware proxy", "Every request enters here")
  Container(pe, "Policy Engine", "OPA", "Allow or deny per request")
  Container(conn, "App Connector", "Private tunnel", "Reaches internal apps")
}
System_Ext(idp, "Identity Provider", "SSO with MFA")
System_Ext(mdm, "Device Management", "Posture: encryption, patches, EDR")
System_Ext(apps, "Internal Apps", "HR, finance, code repos")
System_Ext(siem, "SIEM", "Security logs and alerts")
Rel(employee, proxy, "Requests app", "HTTPS")
Rel(proxy, idp, "Authenticates user")
Rel(proxy, pe, "Asks decision")
Rel(pe, mdm, "Checks device")
Rel(proxy, conn, "Forwards if allowed")
Rel(conn, apps, "Connects")
Rel(pe, siem, "Logs decisions")

Related templates

FlowchartCybersecurity

Security Incident Response Workflow

A security incident response process based on the NIST lifecycle: detect, triage, contain, eradicate, recover and learn.

Data FlowCybersecurity

SIEM Log Pipeline

How security logs from across an organisation reach the SIEM: collection, parsing, enrichment, detection rules and alerts for the SOC.

SequenceCybersecurity

SAML Single Sign-On Login

How SAML single sign-on works when an employee opens a SaaS app: redirect to the company identity provider, MFA and a signed assertion.

NetworkCybersecurity

DMZ Network Architecture

A classic secure network layout: internet-facing services in a DMZ between two firewalls, with internal systems and databases never exposed directly.

MindmapCybersecurity

Threat Model Mindmap (STRIDE)

A STRIDE threat model for a web application, listing example threats in each category with the main mitigations.

State MachineCybersecurity

Vulnerability Management Lifecycle

The life of a vulnerability finding: discovered by a scanner, triaged, assigned, fixed, verified and closed, or accepted as risk.