This document discusses a new security assurance methodology called SECAM that was developed by 3GPP to address security issues in telecommunications networks and products as they transition to using more open IP technologies. SECAM establishes security requirements for both product development processes and the products themselves. It defines roles like manufacturers, purchasers, accreditors, and evaluators and the processes they follow. SECAM requirements are grouped by telecom functions and cover both development processes and product security. Products are evaluated in stages to test for compliance, basic vulnerabilities, and enhanced vulnerabilities. Manufacturers can become accredited and self-declare that their products meet the SECAM requirements.