Water & wastewater · Maintenance Manager · Procurement · Cybersecurity
Expire vendor cryptographic access after water-system maintenance
Does each vendor credential terminate when the approved service task ends?
Operational pain
Integrators need rapid support access, but reusable certificates and shared VPN accounts remain active across multiple facilities.
Trigger
Vendor recertification, support-contract renewal, or discovery of dormant external access.
QNSI contribution
Connect the decision to a controlled security path
Register vendor credentials, certificate chains, service scope, approved dates, facility reach, and responsible sponsor in QNSI.
Decision artifact
A maintenance-access ledger with orphaned trust, overbroad facility scope, and revocation confirmation.
What still requires validation
The utility verifies access-control enforcement, session evidence, break-glass handling, contract clauses, and emergency support.
External problem context
Primary sources
These sources establish the external requirement or risk context. They do not endorse HEOSSI or prove that QNSI completed this scenario.
Evidence boundary
What this page does—and does not—prove
This is a product evaluation pattern, not a customer case study, certification, legal opinion, regulator endorsement, or claim that a production deployment completed the described work.