3GPP TR 33.916

Security Assurance Methodology (SECAM) for 3GPP Network Products
V18.2.0 (2024-06) — Release 18 Methodology

1. Scope

▶

Describes the Security Assurance Methodology (SECAM) — the framework for evaluating security of 3GPP network products. SECAM defines who evaluates, how they evaluate, and what criteria they use.

4. SECAM Framework Overview

▶
┌─────────────────────────────────────────────────────────────┐ │ SECAM Framework │ │ │ │ ┌───────────────┐ ┌───────────────┐ ┌─────────────┐ │ │ │ TR 33.926 │ │ TS 33.117 │ │ TS 33.5xx │ │ │ │ Threat │───►│ General SCAS │───►│ Product │ │ │ │ Analysis │ │ Baseline │ │ Class SCAS │ │ │ └───────────────┘ └───────────────┘ └─────────────┘ │ │ │ │ │ │ │ ▼ ▼ ▼ │ │ ┌─────────────────────────────────────────────────────┐ │ │ │ Evaluation & Testing │ │ │ │ (Performed by accredited test labs) │ │ │ └──────────────────────┬──────────────────────────────┘ │ │ ▼ │ │ ┌─────────────────────────────────────────────────────┐ │ │ │ Security Assurance Report │ │ │ │ (Delivered to operator/vendor) │ │ │ └─────────────────────────────────────────────────────┘ │ └─────────────────────────────────────────────────────────────┘
ComponentDocumentRole
Threat AnalysisTR 33.926Identifies threats and critical assets per product class
General SCASTS 33.117Baseline security requirements applicable to ALL product classes
Product SCASTS 33.5xxPer-product-class additional requirements and test cases
MethodologyTR 33.916 (this)Evaluation process, accreditation, lifecycle

5. Evaluation Process

▶

5.1 Evaluation Steps

  1. Scoping: Vendor identifies product class and applicable SCAS documents
  2. Documentation: Vendor provides Security Target (ST) describing product security features
  3. Testing: Accredited lab executes all applicable test cases from TS 33.117 + TS 33.5xx
  4. Reporting: Lab produces evaluation report with pass/fail per test case
  5. Decision: Evaluation result determines security assurance level

5.2 Evaluation Levels

LevelDescriptionEffort
BasicAutomated testing per SCAS test proceduresLow
EnhancedBasic + manual vulnerability assessment + penetration testingMedium-High

6. Accreditation of Test Laboratories

▶
  • Test labs must be accredited by GSMA NESAS (Network Equipment Security Assurance Scheme)
  • Labs must demonstrate competence in telecom security testing
  • Labs must maintain independence from vendors
  • Re-accreditation required periodically
NESAS: The GSMA Network Equipment Security Assurance Scheme (NESAS) is the industry program that implements SECAM accreditation and vendor self-assessment.

7. Relationship to SCAS Documents

▶
Product ClassSCAS DocumentBaseline
gNB (RAN)TS 33.512TS 33.117
UPF / GWTS 33.513
UDMTS 33.514
AMFTS 33.515
AUSFTS 33.516
SEAFTS 33.517
SMFTS 33.518
NEFTS 33.519
NRFTS 33.521
SEPPTS 33.522

8. Product Lifecycle Security

▶
  • Development: Vendor implements secure development lifecycle (SDL)
  • Evaluation: Product tested against applicable SCAS before deployment
  • Deployment: Operator configures per hardening requirements (TS 33.117 §4.3)
  • Maintenance: Vendor provides vulnerability patches; re-evaluation on major updates
  • End-of-life: Secure decommissioning with key/data destruction