NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Coverage explorer
Coverage meters, assurance chains and the orphan report for candidate AREV-0004.
Elements with at least one active threat
Flows with at least one active threat
Confirmed threats with risk assessment + owner
High/Critical threats with adopted treatment
Adopted remediations with design control + obligation
Obligations with downstream evidence
Assurance chain: TV-000118
Attacker sends unauthorized dosing command
Mitigation pending
SourceSRC-0001NP-200_SystemArchitecture.vsdx, page 3 connector 81MappedSourceSRC-0002dosing-api.openapi.yaml, POST /doseParsedElementAE-000042Infusion dosing command processorFlowDF-000077Remote dosing command (crosses TB-003)ThreatTV-000118Attacker sends unauthorized dosing commandMitigation pendingRiskRSK-000118Inherent Critical 20 / residual High 10 (projected)RemediationREM-201Mutual device/service authenticationAdoptedRemediationREM-202Signed nonce-bound commands + anti-replayAdoptedRemediationREM-203Network allowlist (defense-in-depth)AdoptedControlDC-000314Command authentication requirementControlDC-000315Anti-replay command envelope requirementObligationVOB-000211Authenticated-command fuzz testPendingObligationVOB-000212Auth-bypass penetration testPending
SourceSRC-0001NP-200_SystemArchitecture.vsdx, page 2 connector 55MappedElementAE-000043Drug library storeFlowDF-000079Drug library push (crosses TB-003)ThreatTV-000129Tampered drug library uploadedTreatment plannedRiskRSK-000129Inherent High 15 / residual Medium 5 (projected)RemediationREM-208Signed drug-library packages + version pinningAdoptedControlDC-000318Drug-library signing requirementObligationVOB-000215Drug-library signature verification testIn progress
SourceSRC-0001NP-200_SystemArchitecture.vsdx, page 4 shape 23MappedElementAE-000047Maintenance diagnostic serviceFlowDF-000084Maintenance diagnostic sessionThreatTV-000101Unauthenticated serial service portClosedRiskRSK-000101Inherent High 16 / residual Low 4 (effective)RemediationREM-105Authenticated maintenance accessVerifiedControlDC-000209Authenticated maintenance access requirementObligationVOB-000108Service-port lockdown retest (EVA-000091)Verified
Orphan report
- AE-000053Architecture elementAdvisory
- Issue
- No active threat after TV-000140 dismissal; STRIDE external-system prompts re-run recommended before READY_FOR_REVIEW.
- AE-000048Architecture elementAdvisory
- Issue
- Device provisioning service has no threat linked in candidate; provisioning misuse-case analysis scheduled in triage wave 2.
- DF-000083Data flowAdvisory
- Issue
- EHR order context flow has no active threat linkage; confirm coverage or record justified exclusion (DR-PRN-005).
- REM-216Remediation decisionAdvisory
- Issue
- Deferred without verification obligation; obligations are created at adoption; deferral tracked by escalation date instead.
- TV-000141ThreatAdvisory
- Issue
- Proposed enrichment threat awaiting triage; unresolved proposals block no gate but expire after 30 days per tenant policy.
5 findings