NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
STRIDE register for candidate AREV-0004; a row opens the threat record.
| Segment | Count | Share |
|---|---|---|
| Deterministic | 12 | 75% |
| Enrichment | 3 | 19% |
| Manual | 1 | 6% |
Context: source SRC-0001 (NP-200_SystemArchitecture.vsdx)
- Attacker sends unauthorized dosing commandTV-000118TamperingSpoofingSafetyCriticalMitigation pending
- Owner
- Noor Haddad
- Replay of captured dosing command re-doses patientTV-000124TamperingHighTreatment planned
- Owner
- Noor Haddad
- Unauthenticated serial service port grants privileged shellTV-000101Elevation of privilegeHighClosed
- Owner
- Noor Haddad
- Unsigned application firmware package accepted by update agentTV-000112TamperingElevation of privilegeHighAssessed
- Owner
- Noor Haddad
- Tampered drug library uploaded from compromised pharmacy workstationTV-000129TamperingSafetyHighTreatment planned
- Owner
- Noor Haddad
- Rogue device impersonates clinician app over BLE pairingTV-000126SpoofingHighAssessed
- Owner
- Noor Haddad
- Maintenance actor alters or truncates pump audit logTV-000127RepudiationTamperingMediumTreatment planned
- Owner
- Noor Haddad
- Cloud telemetry stream exposes PHI to unauthorized readerTV-000131Information disclosureMediumTreatment planned
- Owner
- Owen Blake
- Maintenance mode left enabled exposes diagnostic shellTV-000135Elevation of privilegeMediumAssessed
- Owner
- Noor Haddad
- Clinician session fixation on mobile app hand-offTV-000142SpoofingNot assessedProposed
- Owner
- Unassigned
- Time source manipulation skews infusion event timestampsTV-000143RepudiationNot assessedProposed
- Owner
- Unassigned
11 threats