NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Protocol downgrade between gateway and cloud ingestion
PRJ-2026-0042-TV-000138AssessedLow
- Proposed (passed)
- Confirmed (passed)
- Assessed (current)
- Treatment planned (pending)
- Mitigation pending (pending)
- Verified (pending)
- Closed (pending)
A machine-in-the-middle on the egress path attempts TLS downgrade or cipher rollback on gateway-to-cloud sessions to weaken telemetry channel protection.
Deterministic ruleConfidence high
Actor: On-path attacker at hospital egress; high skill.
- On-path position at TB-002.
- Client permits legacy cipher negotiation.
- Intercept session establishment at egress.
- Force renegotiation to weaker parameters.
- Observe or modify telemetry frames.
- Sources
- SRC-0004drawio edge gw-edge->cloud-ingest
- Function
- Cloud channel protection
Inherent
LowL2 × I2
Residual
Not projected
Factors (1 to 5)
Exploitability2
Impact: confidentiality2
Impact: integrity2
Impact: availability1
Impact: authenticity2
Detectability2
| Category | Value | Share |
|---|---|---|
| Exploitability | 2 | 18% |
| Impact: confidentiality | 2 | 18% |
| Impact: integrity | 2 | 18% |
| Impact: availability | 1 | 9% |
| Impact: authenticity | 2 | 18% |
| Detectability | 2 | 18% |
Safety consequence: NoneScope: Single componentUncertainty: Low
- Exploitability
- 2/5
- Requires on-path position at egress plus a client misconfiguration; TLS 1.3-only policy verified.
- Impact: confidentiality
- 2/5
- Telemetry exposure if downgrade succeeded.
- Impact: integrity
- 2/5
- Frame modification bounded by application checks.
- Impact: availability
- 1/5
- None.
- Impact: authenticity
- 2/5
- Channel identity weakened.
- Safety consequence
- None
- No therapy path involvement.
- Affected scope
- Single component
- Gateway egress sessions.
- Detectability
- 2/5
- Handshake anomalies observable in cloud-edge telemetry.
- Uncertainty
- Low
- Build configuration evidence EVA-000061.
Low 4 = L2 x I2; ACCEPT decision requested with compensating control CTRL-001; requires risk owner + Quality approval before effect.
- Responsible implementer
- Owen Blake (Cloud Platform Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- 30 Sept 2026
- Disposition
- Confirmed by Marcus Chen, 15 Apr 2026
- Treatment adopted (pending)
- Implemented (pending)
- Evidence accepted (pending)
- Retest passed (pending)
- Closed (pending)
No remediation options recorded for this threat yet.
EvidenceNot requestedRetestNot scheduled
- Confirmed; risk acceptance requestedMarcus Chen · Low 4 with strong existing control; ACCEPT decision awaiting Quality countersign.
- Proposed by deterministic rule DFL-DOWN-01 (run TMR-0009)system