NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
STRIDE register for candidate AREV-0004; a row opens the threat record.
| Segment | Count | Share |
|---|---|---|
| Deterministic | 12 | 75% |
| Enrichment | 3 | 19% |
| Manual | 1 | 6% |
Context: source SRC-0002 (dosing-api.openapi.yaml)
- Attacker sends unauthorized dosing commandTV-000118TamperingSpoofingSafetyCriticalMitigation pending
- Owner
- Noor Haddad
- Replay of captured dosing command re-doses patientTV-000124TamperingHighTreatment planned
- Owner
- Noor Haddad
- EHR adapter verbose errors leak integration credentialsTV-000140Information disclosureNot assessedDismissed
- Owner
- Unassigned
3 threats