3GPP TR 33.916
Security Assurance Methodology (SECAM) for 3GPP Network Products
V18.2.0 (2024-06) — Release 18 Methodology 1. Scope
▶Describes the Security Assurance Methodology (SECAM) — the framework for evaluating security of 3GPP network products. SECAM defines who evaluates, how they evaluate, and what criteria they use.
4. SECAM Framework Overview
▶
┌─────────────────────────────────────────────────────────────┐
│ SECAM Framework │
│ │
│ ┌───────────────┐ ┌───────────────┐ ┌─────────────┐ │
│ │ TR 33.926 │ │ TS 33.117 │ │ TS 33.5xx │ │
│ │ Threat │───►│ General SCAS │───►│ Product │ │
│ │ Analysis │ │ Baseline │ │ Class SCAS │ │
│ └───────────────┘ └───────────────┘ └─────────────┘ │
│ │ │ │ │
│ ▼ ▼ ▼ │
│ ┌─────────────────────────────────────────────────────┐ │
│ │ Evaluation & Testing │ │
│ │ (Performed by accredited test labs) │ │
│ └──────────────────────┬──────────────────────────────┘ │
│ ▼ │
│ ┌─────────────────────────────────────────────────────┐ │
│ │ Security Assurance Report │ │
│ │ (Delivered to operator/vendor) │ │
│ └─────────────────────────────────────────────────────┘ │
└─────────────────────────────────────────────────────────────┘
| Component | Document | Role |
|---|---|---|
| Threat Analysis | TR 33.926 | Identifies threats and critical assets per product class |
| General SCAS | TS 33.117 | Baseline security requirements applicable to ALL product classes |
| Product SCAS | TS 33.5xx | Per-product-class additional requirements and test cases |
| Methodology | TR 33.916 (this) | Evaluation process, accreditation, lifecycle |
5. Evaluation Process
▶5.1 Evaluation Steps
- Scoping: Vendor identifies product class and applicable SCAS documents
- Documentation: Vendor provides Security Target (ST) describing product security features
- Testing: Accredited lab executes all applicable test cases from TS 33.117 + TS 33.5xx
- Reporting: Lab produces evaluation report with pass/fail per test case
- Decision: Evaluation result determines security assurance level
5.2 Evaluation Levels
| Level | Description | Effort |
|---|---|---|
| Basic | Automated testing per SCAS test procedures | Low |
| Enhanced | Basic + manual vulnerability assessment + penetration testing | Medium-High |
6. Accreditation of Test Laboratories
▶- Test labs must be accredited by GSMA NESAS (Network Equipment Security Assurance Scheme)
- Labs must demonstrate competence in telecom security testing
- Labs must maintain independence from vendors
- Re-accreditation required periodically
NESAS: The GSMA Network Equipment Security Assurance Scheme (NESAS) is the industry program that implements SECAM accreditation and vendor self-assessment.
7. Relationship to SCAS Documents
▶8. Product Lifecycle Security
▶- Development: Vendor implements secure development lifecycle (SDL)
- Evaluation: Product tested against applicable SCAS before deployment
- Deployment: Operator configures per hardening requirements (TS 33.117 §4.3)
- Maintenance: Vendor provides vulnerability patches; re-evaluation on major updates
- End-of-life: Secure decommissioning with key/data destruction