QNSI

Water & wastewater | Modelled case study

Expire vendor cryptographic access after water-system maintenance

Does each vendor credential terminate when the approved service task ends?

Accountable ownersMaintenance Manager · Procurement · Cybersecurity
Scenario typeComposite model
Required outputDecision artifact

The modelled organisation

A recognisable problem reaches the operating agenda

This composite scenario follows the Maintenance Manager · Procurement · Cybersecurity functions. It is grounded in the cited problem context but does not identify a real customer.

Operating environment

A water utility operates treatment plants, pumping stations, reservoirs, remote PLC gateways, engineering workstations, telemetry, and vendor maintenance links.

What is at stake

Control and recovery must remain available during facility loss, communications degradation, or supplier intervention without leaving permanent shared access behind.

Situation

Integrators need rapid support access, but reusable certificates and shared VPN accounts remain active across multiple facilities.

Event that forces action

Vendor recertification, support-contract renewal, or discovery of dormant external access.

Concrete system boundary

Systems this case study puts in scope

The model is specific about the operational surfaces that must be discovered, changed, or independently checked.

01

vendor identities

02

maintenance VPN or jump host

03

approved treatment assets

04

service-task expiry and revocation evidence

Modelled case study walkthrough

How this organisation would use QNSI

The walkthrough connects the real-world problem to a bounded QNSI contribution and an independently reviewable result.

01

Recognise the operating condition

Integrators need rapid support access, but reusable certificates and shared VPN accounts remain active across multiple facilities.

02

Frame the decision the owners must make

Does each vendor credential terminate when the approved service task ends?

03

Apply QNSI to the controlled boundary

Register vendor credentials, certificate chains, service scope, approved dates, facility reach, and responsible sponsor in QNSI.

04

Leave the team with a concrete result

A maintenance-access ledger with orphaned trust, overbroad facility scope, and revocation confirmation.

05

Prove the result in the organisation's environment

The utility verifies access-control enforcement, session evidence, break-glass handling, contract clauses, and emergency support.

What useful success looks like

A decision artifact plus proof from the real environment

The model stops at a target result. It becomes an actual case study only when a customer produces and independently validates this evidence in production.

Decision artifact

A maintenance-access ledger with orphaned trust, overbroad facility scope, and revocation confirmation.

Independent validation boundary

The utility verifies access-control enforcement, session evidence, break-glass handling, contract clauses, and emergency support.

Real-world problem grounding

Primary sources behind the model

These sources establish the external requirement, failure mode, or risk context used to model this case. They do not endorse HEOSSI or prove that QNSI completed the scenario.

Customer evidence status

This is modelled, not a customer claim

The organisation is a composite and the result is a target state. This page does not prove a deployment, customer outcome, certification, legal conclusion, regulator endorsement, or completed control.

QNSI privacy choices

Necessary storage keeps the site secure. With your permission, privacy-bounded analytics help HEOSSI understand pages, journeys, and campaign outcomes. No advertising profiles are created.

Cookie policy