TARA – Threat Analysis and Risk Assessment according to ISO/SAE 21434
A Threat Analysis and Risk Assessment (TARA) identifies cybersecurity assets, damage scenarios, threat scenarios, and attack paths, and evaluates impact and attack feasibility to determine cybersecurity risk. It is the central risk assessment method required by ISO/SAE 21434 and the foundation for cybersecurity goals and requirements. PRAETORIO performs TARAs for automotive and embedded systems, and reviews existing TARAs for completeness and methodological soundness.
Our TARA work is grounded in the actual system architecture: the E/E interfaces, communication buses, and software components involved: not a generic threat catalogue applied without regard to the specific product.
Request a TARA for Your Item or ComponentWhat a TARA Is
A TARA is a structured, repeatable method for identifying and rating cybersecurity risk. Under ISO/SAE 21434, it produces a documented, traceable basis for cybersecurity goals and requirements. A TARA covers:
- Assets: the parts of a system that, if compromised, would result in a damage scenario (e.g. an ECU, a communication interface, a cryptographic key store, sensor data).
- Damage scenarios: the negative consequences at vehicle or operational level if an asset’s cybersecurity property (confidentiality, integrity, availability) is compromised.
- Threat scenarios: how a cybersecurity property of an asset could realistically be compromised.
- Attack paths: the sequence of steps an attacker would need to complete a threat scenario, often across multiple assets or interfaces.
- Impact rating: the severity of a damage scenario across safety, financial, operational, and privacy categories.
- Attack feasibility rating: how practical an attack path is to execute, considering required expertise, equipment, time, and knowledge of the target.
- Risk determination: combining impact and attack feasibility into a risk value that determines whether risk treatment (avoid, reduce, share, or accept) is required.
Why TARA Matters
It is the entry point for all downstream cybersecurity engineering. Cybersecurity goals, cybersecurity requirements, and the cybersecurity concept are all derived from TARA results. An incomplete or poorly scoped TARA propagates gaps through the entire cybersecurity case.
It is explicitly required by ISO/SAE 21434 and, by extension, by most OEM cybersecurity requirements placed on suppliers. A missing or superficial TARA is one of the most common findings in supplier cybersecurity audits.
It surfaces risk while it is still cheap to address. Identifying an attack path during concept or architecture phase allows a mitigating design decision; the same finding after production start typically requires a far more expensive retrofit or field action.
It must be revisited when the system changes. A new interface, a software update introducing new functionality, or a newly disclosed vulnerability class can invalidate an existing TARA’s assumptions, requiring a re-assessment of specific assets or threat scenarios.
Our Approach
PRAETORIO performs a TARA following the method defined in ISO/SAE 21434:
- Item and scope definition: define the item boundary, its operational environment, and the assumptions the TARA relies on.
- Asset identification: identify the assets within the item, and the cybersecurity properties (confidentiality, integrity, availability) relevant to each.
- Damage scenario identification: determine the negative consequences at vehicle or operational level if each asset’s cybersecurity property is compromised.
- Threat scenario identification: determine how each asset’s cybersecurity property could realistically be compromised.
- Attack path analysis: map the attack paths that would allow a threat scenario to be realized, including required preconditions.
- Impact rating: rate each damage scenario’s severity across safety, financial, operational, and privacy impact categories.
- Attack feasibility rating: rate each attack path’s feasibility based on elapsed time, specialist expertise, knowledge of the item, window of opportunity, and equipment required.
- Risk determination: combine impact and attack feasibility ratings into a risk value for each threat scenario.
- Cybersecurity goal definition: define cybersecurity goals for risks that require treatment.
- Cybersecurity requirement derivation: translate cybersecurity goals into verifiable technical requirements, handed off to the cybersecurity concept and requirements engineering workstream.
- Traceability and documentation: document the full TARA with traceability from asset through requirement, structured for audit and reuse.
Deliverables
- TARA report
- Asset list with cybersecurity properties
- Damage scenario catalogue
- Threat scenario catalogue
- Attack path documentation
- Impact and attack feasibility ratings
- Risk determination results
- Cybersecurity goals (handoff to requirements engineering)
- Traceability matrix
How PRAETORIO Can Support Your Team
- Full execution of a TARA for a specific item, ECU, or component, from scoping through risk determination and cybersecurity goals.
- Augmentation of an existing engineering team, contributing TARA methodology expertise for a specific phase (e.g. attack feasibility rating) without owning the full assessment.
- Review of an existing TARA, checking asset coverage, methodology consistency, and traceability against ISO/SAE 21434 expectations.
- Gap analysis comparing an existing risk assessment approach against the ISO/SAE 21434 TARA method.
- Workshops on TARA methodology for engineering teams building internal TARA capability.
- Method and template definition, establishing a repeatable TARA process and documentation structure for ongoing use across a product line.
Typical Use Cases
- A new ECU or embedded controller requiring a first TARA before program approval.
- An existing product where a new interface or feature (e.g. added connectivity) requires re-assessment of specific assets.
- A supplier providing a TARA as part of an OEM cybersecurity evidence package.
- A component supplier needing to demonstrate cybersecurity risk assessment to a Tier-1 or OEM customer.
- An organization with an informal or inconsistent risk assessment process seeking a documented, ISO/SAE 21434-aligned TARA method.
- A legacy platform requiring a retrofit TARA ahead of a facelift, derivative, or newly disclosed vulnerability.
Why PRAETORIO
- Embedded systems and automotive engineering background, so attack paths are identified based on how the system actually works, not from a generic checklist.
- More than 15 years of experience across embedded C/C++, AUTOSAR, and power electronics: this technical depth shapes more realistic threat scenarios and attack feasibility ratings.
- Direct, hands-on TARA delivery experience across asset identification, threat modeling, attack path and attack feasibility analysis, and cybersecurity requirements derivation.
- Traceability-first documentation: every risk determination is traceable back to a specific asset and forward to a cybersecurity requirement, supporting audit readiness.
Related Services
- ISO/SAE 21434 Consulting: the standard defining the TARA method
- Cybersecurity Engineering: the overall cybersecurity engineering practice
- Automotive Cybersecurity: broader embedded and automotive cybersecurity engineering
- Cyber Resilience Act Consulting: where CRA risk assessment expectations overlap with TARA methodology
- Functional Safety Consulting: coordinating safety and security risk assessment
- Systems Engineering: system architecture as the basis for asset identification
FAQ
What is a TARA according to ISO/SAE 21434?
A Threat Analysis and Risk Assessment (TARA) is the structured method ISO/SAE 21434 defines for identifying cybersecurity assets, damage scenarios, and threat scenarios, analyzing attack paths, and rating impact and attack feasibility to determine cybersecurity risk. Its outputs become the basis for cybersecurity goals and requirements.
When is a TARA required?
A TARA is required for any item or component in scope of ISO/SAE 21434, typically at concept phase for new development, and again whenever a change (new interface, added functionality, or a newly disclosed vulnerability) could affect previously assessed assets or threat scenarios. OEMs commonly require a TARA as part of supplier cybersecurity evidence regardless of a specific legal mandate.
What are assets in an ISO/SAE 21434 TARA?
Assets are the parts of a system whose compromise (loss of confidentiality, integrity, or availability) would lead to a damage scenario. Typical automotive examples include ECUs, communication interfaces (CAN, Ethernet, wireless), cryptographic keys and certificates, firmware, calibration data, and diagnostic access points.
What is the difference between a damage scenario and a threat scenario?
A damage scenario describes the negative consequence at vehicle or operational level (e.g. loss of steering control, unauthorized data disclosure). A threat scenario describes how a cybersecurity property of an asset could be compromised to cause that damage scenario (e.g. spoofed CAN messages exploiting a lack of message authentication). Damage scenarios describe impact; threat scenarios describe cause.
How is attack feasibility evaluated?
Attack feasibility is rated based on factors defined in ISO/SAE 21434, typically including elapsed time to carry out the attack, specialist expertise required, knowledge of the item needed, window of opportunity, and equipment required. Higher feasibility (an attack that is easier to carry out) combined with higher impact produces higher risk.
Can PRAETORIO review an existing TARA?
Yes. PRAETORIO reviews existing TARA reports for asset coverage, consistency of methodology, correctness of impact and attack feasibility ratings, and traceability to cybersecurity requirements, and identifies specific gaps ahead of an OEM audit or internal release gate.
Can a TARA be performed for an existing product?
Yes. A retrofit TARA is common for legacy products newly facing OEM cybersecurity requirements, entering Cyber Resilience Act scope, or undergoing a facelift or derivative program. The scope typically focuses on assets and interfaces that are new, changed, or previously unassessed.
How long does a TARA take?
Duration depends on the number of assets, interfaces, and threat scenarios in scope. A focused TARA for a single ECU with a limited interface set can often be completed in a few weeks; a full item-level TARA for a complex, networked system takes longer. Scoping is part of the initial engagement.
Need a TARA for Your Item or Component?
PRAETORIO can support your team from asset identification and threat analysis through risk determination and cybersecurity requirement definition. Contact us to discuss your project.
Contact Us