Skip to content

GLOSSARY

TARA

Threat Analysis and Risk Assessment

TARA is defined formally within ISO/SAE 21434 for road vehicles, and equivalent structured threat and risk assessment activity is expected under the CRA and standards such as IEC 62443. The method identifies assets, damage scenarios, threat scenarios and attack paths, then rates impact and attack feasibility to determine a risk value that drives the security requirements applied to the design.

The steps typically involved

  • Asset identification: what needs protecting, and the cybersecurity properties that matter for each asset.
  • Threat scenario identification, often structured against categories such as spoofing, tampering or denial of service.
  • Impact rating, considering safety, financial, operational and privacy consequences.
  • Attack feasibility rating, considering the effort, expertise and access an attacker would need.
  • Risk determination and treatment decision: avoid, reduce, share or accept.

TARA output feeds directly into the cybersecurity requirements attached to the architecture, in the same way hazard analysis feeds safety requirements. Treating it as a one-off document rather than a maintained analysis undermines its value, since new attack paths and component changes over the product's life change the risk picture.

A defensible TARA records its assumptions about the operating environment and attacker capability explicitly, since these assumptions are what a reviewer will challenge first.