Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

Time source manipulation skews infusion event timestamps

PRJ-2026-0042-TV-000143Proposed

  1. Proposed (current)
  2. Confirmed (pending)
  3. Assessed (pending)
  4. Treatment planned (pending)
  5. Mitigation pending (pending)
  6. Verified (pending)
  7. Closed (pending)

Manipulating the device time source would skew audit and infusion event timestamps, weakening event correlation and repudiation resistance across the fleet record.

Deterministic ruleConfidence medium

Actor: Network attacker able to spoof NTP or gateway time sync.

Elements
AE-000044Pump audit log storeAE-000051NimbusLink Gateway edge service
Flows
DF-000075Audit event write
Sources
SRC-0001VSDX page 4 shape 12 (audit dependency)
Function
Event time integrity