TR 33.936
Security Assurance Methodology (SECAM) for 3GPP Virtualized Network Products

V18.0.1 (Wzip)  2023/03  19 p.
Mr. Qi, Minpeng
China Mobile Com. Corporation

full Table of Contents for  TR 33.936  Word version:  18.0.1

1  Scope

The present document defines the complete Security Assurance Methodology (SECAM) evaluation process (evaluation, relation to SECAM Accreditation Body, roles, etc.) as well as the components of SECAM that are intended to provide the expected security assurance for virtualized network product. It will thus describe the general scheme providing an overview of the entire scheme and explaining how to create and apply the Security Assurance Specifications (SCASs). It will detail the different evaluation tasks (vendor network product development and network product lifecycle management process assessment, Security Compliance Testing, Basic Vulnerability Testing and Enhanced Vulnerability Analysis) and the different actors involved. Enhanced Vulnerability Analysis is outside the scope of the present release of SECAM. The present document will help all involved parties to have a clear understanding of the overall process and the covered threats.
In another aspect, compared to [2], present document shows specific methodology to virtualized network product in addition.

2  References

3  Definitions of terms, symbols and abbreviations

3.1  Terms

3.2  Symbols

3.3  Abbreviations

4  Overview

5  Security Assurance Specification (SCAS) Creation

6  Vendor development and product lifecycle processes and test laboratory accreditation

7  Evaluation and SCAS instantiation

