Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review

Threat workbench

STRIDE register for candidate AREV-0004; a row opens the threat record.

Threats by generation origin
SegmentCountShare
Deterministic1275%
Enrichment319%
Manual16%
Context: source SRC-0002 (dosing-api.openapi.yaml)
  • Attacker sends unauthorized dosing commandTV-000118TamperingSpoofingSafety
    CriticalMitigation pending
    Owner
    Noor Haddad
  • Replay of captured dosing command re-doses patientTV-000124Tampering
    HighTreatment planned
    Owner
    Noor Haddad
  • EHR adapter verbose errors leak integration credentialsTV-000140Information disclosure
    Not assessedDismissed
    Owner
    Unassigned
3 threats