Navigation and service

Procedure

Overview of NESAS CCS-GI

In the sequence of pictures, the interaction of all participants and the steps of the process are displayed and briefly explained. A detailed process flow can be found in the schematic documents.

As shown in the sequence of pictures, the procedure comprises two testing activities. First, the software development and life cycle processes are audited, then the concrete product is evaluated. The product evaluation is based on the Security Assurance Specifications (SCAS) for standardised functions specified by the 3rd Generation Partnership Project (3GPP). It is possible to use the audit for several product evaluations for products which were developed according to the same processes. This saves costs and time for all parties involved.

As a result of the audit activities, the certification body has reliable security statements about the product and also the processes under which this product is developed and maintained. This allows the certification body for the first time to extend the validity of certificates beyond the actual evaluated product version, provided the equipment vendor only makes "minor updates" to improve or restore security performance of its product. This is possible for the entire duration of the certificate, which is two years, without the need for explicit recertification by the BSI. The equipment vendor must report these minor updates in advance to the test laboratory, together with an impact analysis. The testing laboratory then prepares a vote for the certification body, which finally decides whether the update is indeed minor.

Contact

Federal Office for Information Security
Devision S 26 - BSZ, NESAS Certification
Postbox 20 03 63
53133 Bonn, Germany

Telephone: 0800 274 1000
Telefax: +49 228 99 9582-5455
E-Mail: nesas@bsi.bund.de

Public key for nesas@bsi.bund.de

Key-ID: DE67 9D20 ECC1 27ED
Fingerprint: 6328 7428 47E4 9283 3346 C7BC DE67 9D20 ECC1 27ED