Energy & electric grid · OT Access Management · Vendor Risk · Operations
Constrain supplier remote-access trust in electric operations
Which supplier identity can reach which asset, for what task, using which credential and approval?
Operational pain
Emergency vendor accounts and shared support certificates persist across substations and generation sites after the original work ends.
Trigger
Supplier onboarding, access recertification, merger, or remote-access incident.
QNSI contribution
Connect the decision to a controlled security path
Inventory supplier cryptographic identities, endpoints, issuers, validity, owner, and authorized service window in QNSI.
Decision artifact
A vendor trust ledger exposing shared credentials, expired work orders, overbroad reach, and revocation evidence.
What still requires validation
The operator tests enforcement at jump hosts and endpoints, session monitoring, emergency approval, and contract controls.
External problem context
Primary sources
These sources establish the external requirement or risk context. They do not endorse HEOSSI or prove that QNSI completed this scenario.
Evidence boundary
What this page does—and does not—prove
This is a product evaluation pattern, not a customer case study, certification, legal opinion, regulator endorsement, or claim that a production deployment completed the described work.