NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Back to source intakeMapping studio: 2 of 3 confirmed
NP-200_SystemArchitecture.vsdx
SRC-0001Microsoft Visio (.vsdx)semantic sourceMapped
- Uploaded (passed)02 Apr
- Scanned (passed)02 Apr
- Parsed (passed)02 Apr
- Mapped (passed)06 Apr
- Accepted (pending)
- Source id
- SRC-0001
- External version
- Rev H (candidate)
- Source system
- Meridian PLM vault
- Author
- Priya Raman (Security Architect)
- Captured
- 01 Apr 2026
- Uploaded
- Priya Raman, 02 Apr 2026, 09:14 UTC
- WarningVSDX-W014Connector without explicit direction; direction inferred from arrowhead.page 3 connector 88
- WarningVSDX-W021Layer "Draft-Notes" excluded from semantic extraction per profile.page 5 layer 2
- InfoVSDX-I003Custom property "SafetyClass" mapped to safety-relevance flag on 4 shapes.
Elements
- AE-000042Infusion dosing command processorVSDX page 3 shape 41
- AE-000041Pump motor controllerVSDX page 3 shape 44
- AE-000043Drug library storeVSDX page 3 shape 47
- AE-000044Pump audit log storeVSDX page 4 shape 12
- AE-000045Firmware update agentVSDX page 4 shape 18
- AE-000046BLE interface controllerVSDX page 3 shape 39
- AE-000047Maintenance diagnostic serviceVSDX page 4 shape 23
- AE-000051NimbusLink Gateway edge serviceVSDX page 2 shape 17
- AE-000052Clinician mobile appVSDX page 2 shape 09
- AE-000053Hospital EHR integration adapterVSDX page 2 shape 05
- AE-000054Pharmacy drug-library workstationVSDX page 2 shape 21
- AE-000055Field service laptopManual addition (gap DR-GATE-005 justification, 07 Apr 2026)
- AE-000061Cloud telemetry ingestion serviceVSDX page 5 shape 08
- AE-000062Fleet update distribution serviceVSDX page 5 shape 11
- AE-000048Device provisioning serviceVSDX page 4 shape 31
Data flows
- DF-000077Remote dosing commandVSDX page 3 connector 81
- DF-000071BLE clinician sessionVSDX page 3 connector 74
- DF-000072Local dosing confirmationVSDX page 3 connector 76
- DF-000073Dosing actuationVSDX page 3 connector 78
- DF-000074Drug library readVSDX page 3 connector 79
- DF-000075Audit event writeVSDX page 4 connector 31
- DF-000079Drug library pushVSDX page 2 connector 55
- DF-000081Telemetry uploadVSDX page 5 connector 12
- DF-000082Firmware package deliveryVSDX page 5 connector 17
- DF-000083EHR order contextVSDX page 2 connector 49
- DF-000084Maintenance diagnostic sessionManual addition with AE-000055 (07 Apr 2026)
- Merge proposed: page 2 shape 17 "Edge Svc" with SRC-0004 node "gw-edge" (AE-000051).
- TV-000118Attacker sends unauthorized dosing commandMitigation pending
- TV-000112Unsigned application firmware package accepted by update agentAssessed
- TV-000124Replay of captured dosing command re-doses patientTreatment planned
- TV-000126Rogue device impersonates clinician app over BLE pairingAssessed
- TV-000127Maintenance actor alters or truncates pump audit logTreatment planned
- TV-000133Gateway flood starves dosing command channelTreatment planned
- TV-000135Maintenance mode left enabled exposes diagnostic shellAssessed
- TV-000143Time source manipulation skews infusion event timestampsProposed
- TV-000101Unauthenticated serial service port grants privileged shellClosed
- Deterministic threat generation consumed source (run TMR-0009)Sourcesystem
- Mapping confirmed for 44 of 46 extracted elementsSourcePriya Raman
- Parse completed (visio-vsdx 4.2.1), 3 warningsSourcesystem
- Malware scan clean; MIME/magic verified; content-addressedSourcesystem
- Uploaded Rev H from Meridian PLM vaultSourcePriya Raman