Phase | Sub-phase | Deliverable | Published by |
---|---|---|---|
Methodology building | Consensus on threats | 3GPP | |
Security Assurance process | |||
Security Assurance Specifications | |||
Test methodology and skills requirements | SECAM Accreditation Body / GSMA | ||
Test laboratories accreditation and monitoring rules | |||
Network product development and network product lifecycle management Process Assurance requirements | |||
Accreditation | Methodology Accreditation | Accreditation report | Accreditor |
Audit and accreditation | Evidence of successful accreditation of vendor network product development and network product lifecycle management process Evidence of successful accreditation of Security Compliance test laboratories Evidence of successful accreditation of Basic Vulnerability Test laboratories | SECAM Accreditation Body / GSMA | |
Evaluation | SCAS instantiation | Instantiation of SCAS | Vendor |
Vendors Development process compliance | For the accreditation: Design documentation [free-form] Operational guidance [free-form] Version and configuration management plan [free-form] Flaw remediation documentation [free-form] Process to ensure code quality documentation [free-form] Vendor's development sites protection [free form] Before any network product evaluation: Network Product Development and network product lifecycle management process self-evaluation report providing evidences that the network product was developed under the accredited process [free-form] | ||
Security compliance testing | Security Compliance Testing report | Vendor or third-party | |
Basic Vulnerability Testing | Basic Vulnerability Testing report | ||
Self-declaration | Self-declaration | Self-declaration | Vendor |
Monitoring, dispute resolution | Informal guidance document. Accreditation revocation list | SECAM Accreditation Body / GSMA | |
Dispute resolution | - | Operator claims |
Actor | Tasks and Responsibilities |
---|---|
3GPP |
Describe SECAM in the security assurance process documentation (i.e. the present document)
Provide SCASes for individual Network Product Classes:
|
SECAM Accreditation Body | Describe the rules for accreditation and monitoring of development and test laboratories. Develop Vendor network product development and network product lifecycle management process assurance requirements as well as related evaluation activities generic to all network product classes in a dedicated document. Assess the skills of the test laboratory in conducting an evaluation for conformance to 3GPP SCAS requirements for a given network product class or range of classes; This includes assessing the test laboratory's skill in selecting tools for performing the evaluation. Assess the test laboratory's ability to comply with the test methodology (for security compliance Testing and Basic Vulnerability Testing laboratories). Administer the evaluation of the security relevant part of the Vendor network product development and network product lifecycle management process during an initial accreditation. Provide a process to resolve conflicts. |
(Accredited) Vendor |
Ensure Vendor network product development and network product lifecycle management process assurance compliance.
Provide SCAS instantiation document.
Provide self-declaration after evaluation:
|
(Accredited) Vendor or (accredited) third-party Test laboratory |
All Test laboratories:
|
Operator | Operator security acceptance decision: Examines the network product, the compliance reports and the test laboratories accreditation published by the SECAM Accreditation Body and decides if the results are sufficient according to its internal policies. |