NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
STRIDE register for candidate AREV-0004; a row opens the threat record.
| Segment | Count | Share |
|---|---|---|
| Deterministic | 12 | 75% |
| Enrichment | 3 | 19% |
| Manual | 1 | 6% |
Context: element AE-000051 (NimbusLink Gateway edge service)
- Attacker sends unauthorized dosing commandTV-000118TamperingSpoofingSafetyCriticalMitigation pending
- Owner
- Noor Haddad
- Replay of captured dosing command re-doses patientTV-000124TamperingHighTreatment planned
- Owner
- Noor Haddad
- Gateway flood starves dosing command channelTV-000133Denial of serviceHighTreatment planned
- Owner
- Owen Blake
- Cloud telemetry stream exposes PHI to unauthorized readerTV-000131Information disclosureMediumTreatment planned
- Owner
- Owen Blake
- Protocol downgrade between gateway and cloud ingestionTV-000138TamperingInformation disclosureLowAssessed
- Owner
- Owen Blake
- EHR adapter verbose errors leak integration credentialsTV-000140Information disclosureNot assessedDismissed
- Owner
- Unassigned
- Shared service account between gateway services enables lateral movementTV-000141Elevation of privilegeNot assessedProposed
- Owner
- Unassigned
- Time source manipulation skews infusion event timestampsTV-000143RepudiationNot assessedProposed
- Owner
- Unassigned
8 threats