NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Maintenance actor alters or truncates pump audit log
PRJ-2026-0042-TV-000127Treatment plannedMedium
- Proposed (passed)
- Confirmed (passed)
- Assessed (passed)
- Treatment planned (current)
- Mitigation pending (pending)
- Verified (pending)
- Closed (pending)
A field-service actor in maintenance mode (OPST-003) with diagnostic shell access modifies or truncates the device audit log store, undermining clinical event reconstruction and repudiating dosing history. Current audit logging (CTRL-005) has no tamper evidence.
Deterministic ruleConfidence high
Actor: Authorized maintenance actor misusing access, or attacker with stolen service credentials; physical access.
- Maintenance mode active.
- Diagnostic shell reachable via DF-000084.
- Enter maintenance mode with service credentials.
- Access log partition via diagnostic tooling.
- Rewrite or truncate segments; absence of hash chaining hides the change.
- Sources
- SRC-0001VSDX page 4 shape 12 / connector 31
- Function
- Audit and clinical event reconstruction
Inherent
MediumL3 × I3
Residual
MediumL2 × I3
Factors (1 to 5)
Exploitability3
Impact: confidentiality2
Impact: integrity3
Impact: availability1
Impact: authenticity3
Detectability4
| Category | Value | Share |
|---|---|---|
| Exploitability | 3 | 19% |
| Impact: confidentiality | 2 | 13% |
| Impact: integrity | 3 | 19% |
| Impact: availability | 1 | 6% |
| Impact: authenticity | 3 | 19% |
| Detectability | 4 | 25% |
Safety consequence: NoneScope: Single deviceUncertainty: Low
- Exploitability
- 3/5
- Requires maintenance-mode access; service credentials shared across region teams today.
- Impact: confidentiality
- 2/5
- Log content readable in maintenance mode regardless.
- Impact: integrity
- 3/5
- History alterable without detection.
- Impact: availability
- 1/5
- No delivery effect.
- Impact: authenticity
- 3/5
- Event attribution destroyed.
- Safety consequence
- None
- No direct therapy effect; investigation integrity impact only.
- Affected scope
- Single device
- Per-device log store.
- Detectability
- 4/5
- Currently undetectable post-hoc; improves to detectable with hash chaining.
- Uncertainty
- Low
- Design verified from source.
Medium 9 = L3 x I3; treatment adopted (REM-220).
- Responsible implementer
- Noor Haddad (Firmware Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- 15 Jul 2026
- Disposition
- Confirmed by Marcus Chen, 15 Apr 2026
- Treatment adopted (passed)
- Implemented (current)
- Evidence accepted (pending)
- Retest passed (pending)
- Closed (pending)
- REM-220Hash-chained tamper-evident audit segmentsAdopted
- VOB-000220Audit-chain integrity verification testPendingdue 07 Aug 2026
EvidenceNot requestedRetestNot scheduled
- Treatment adoptedTomas Novak · REM-220 hash-chained audit segments adopted; VOB-000220 created.
- ConfirmedMarcus Chen
- Proposed by deterministic rule DST-REP-02 (run TMR-0009)system