Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

Maintenance actor alters or truncates pump audit log

PRJ-2026-0042-TV-000127Treatment plannedMedium

  1. Proposed (passed)
  2. Confirmed (passed)
  3. Assessed (passed)
  4. Treatment planned (current)
  5. Mitigation pending (pending)
  6. Verified (pending)
  7. Closed (pending)

A field-service actor in maintenance mode (OPST-003) with diagnostic shell access modifies or truncates the device audit log store, undermining clinical event reconstruction and repudiating dosing history. Current audit logging (CTRL-005) has no tamper evidence.

Deterministic ruleConfidence high

Actor: Authorized maintenance actor misusing access, or attacker with stolen service credentials; physical access.

Elements
AE-000044Pump audit log storeAE-000047Maintenance diagnostic service
Flows
DF-000075Audit event writeDF-000084Maintenance diagnostic session
Sources
SRC-0001VSDX page 4 shape 12 / connector 31
Function
Audit and clinical event reconstruction