<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security-Testing on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/security-testing/</link><description>Recent content in Security-Testing on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/security-testing/index.xml" rel="self" type="application/rss+xml"/><item><title>3GPP SCAS</title><link>https://lesitedefrancois.be/en/compliance/scas/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/scas/</guid><description>&lt;p&gt;&lt;strong&gt;3GPP Security Assurance Specifications (SCAS)&lt;/strong&gt; are technical specifications developed by &lt;strong&gt;3GPP&amp;rsquo;s SA3 working group&lt;/strong&gt; (Security) that define security requirements and associated test cases for specific network product classes — each 3GPP-defined network function (AMF, SMF, UPF, gNB, MME, etc.) has its own SCAS document. 3GPP is the &lt;strong&gt;international&lt;/strong&gt; standards body responsible for mobile telecommunications standards (comprising seven organizational partners covering Europe, US, China, Japan, Korea, India), making SCAS a globally recognized specification set rather than a national or regional scheme. Each SCAS document follows a structured approach: it identifies the &lt;strong&gt;assets&lt;/strong&gt; of the network product class that require protection, performs a &lt;strong&gt;threat analysis&lt;/strong&gt; describing how those assets can be exploited, defines &lt;strong&gt;security requirements&lt;/strong&gt; (objectives) that mitigate the identified threats, and specifies concrete &lt;strong&gt;test cases&lt;/strong&gt; to verify that a product implementation meets those requirements. SCAS specifications serve as the technical foundation for the &lt;strong&gt;GSMA NESAS&lt;/strong&gt; scheme — when a vendor submits a network product for NESAS evaluation, accredited test laboratories evaluate it against the applicable SCAS test cases. Compliance is &lt;strong&gt;voluntary&lt;/strong&gt; (there is no legal mandate to pass SCAS tests), but SCAS/NESAS evaluation results are increasingly used as a procurement requirement by telecom operators and are referenced by the EU 5G Security Toolbox and national security assessments. The list of adopted SCAS documents is maintained by the GSMA in FS.63 and continues to expand as 3GPP defines new network functions.&lt;/p&gt;</description></item></channel></rss>