Skip to content

GUIDE · Product security

ISO/SAE 21434 automotive cybersecurity

ISO/SAE 21434 mirrors the functional safety lifecycle in structure, which is deliberate and makes coordinating the two disciplines tractable rather than duplicative.

LAST REVIEWED

Scope and relationship to regulation

ISO/SAE 21434 specifies cybersecurity engineering requirements for road vehicle electrical and electronic systems across the full lifecycle: concept, development, production, operation, maintenance and decommissioning. It is closely linked to UN Regulation No. 155 on cybersecurity management systems, which many markets require vehicle manufacturers to hold type approval against; ISO/SAE 21434 is widely used as the technical basis for demonstrating compliance with that regulation, though the regulation and the standard are formally distinct instruments.

The cybersecurity risk assessment (TARA)

The standard's central technical activity is the threat analysis and risk assessment (TARA), which identifies assets, threat scenarios, attack paths and their feasibility, and the impact of a successful attack across safety, financial, operational and privacy dimensions. The combination of impact and attack feasibility determines a risk value, which in turn drives the cybersecurity goals and requirements allocated to the system. This mirrors the hazard analysis and risk assessment structure in ISO 26262 closely enough that organisations running both processes can share analysis infrastructure and, in places, reviewers.

  • Asset identification: components, data and functions whose compromise would have a defined impact.
  • Threat scenario identification: how an asset's cybersecurity properties (confidentiality, integrity, availability) could be violated.
  • Attack path analysis and feasibility rating: how an attacker could realise a threat scenario and how feasible that is given required attacker capability, resources and time.
  • Impact rating: consequence of a successful attack across safety, financial, operational and privacy categories.
  • Risk value determination and treatment decision: avoid, reduce, share/transfer, or retain the risk, with rationale recorded.

Cybersecurity Assurance Levels and the wider lifecycle

Cybersecurity goals derived from the TARA are typically associated with Cybersecurity Assurance Levels (CAL), which influence the rigour expected in subsequent verification and validation activities, in a manner analogous to how ASIL influences rigour in ISO 26262. The standard also requires a cybersecurity management system at the organisational level, covering governance, competence, tool management, and continuous monitoring for new threats and vulnerabilities affecting fielded vehicles — the automotive-sector equivalent of the CRA's vulnerability handling expectations for other product categories.

Coordinating safety and security work

Where a cybersecurity threat could plausibly lead to a safety hazard — for example, a compromised braking or steering function — the TARA and the ISO 26262 hazard analysis need to inform each other, since a security vulnerability can be the initiating cause of a safety-relevant malfunction that the safety analysis alone would not anticipate. Organisations that run these analyses in isolation, using disconnected tools and vocabularies, routinely miss this class of combined hazard. A shared asset and function model, reviewed jointly by safety and security engineers, is the most reliable way to close this gap.

Common failure modes

  • TARA performed once at concept stage and not revisited as the architecture or threat landscape changes.
  • Attack feasibility ratings estimated without a consistent, documented method, making risk values hard to defend under audit.
  • Cybersecurity requirements defined without traceability to the specific threat scenario they mitigate.
  • Post-production monitoring for new vulnerabilities treated as a general IT security activity rather than a defined process feeding back into the vehicle's cybersecurity case.
  • Safety and security teams working from separate hazard/threat catalogues with no reconciliation process.

What auditors and assessors expect

Assessors expect a documented cybersecurity management system operating at the organisational level, TARA outputs that are traceable to cybersecurity goals and requirements, verification and validation evidence appropriate to the assigned CAL, and evidence of ongoing monitoring and incident response for vehicles already in the field. As with ISO 26262, the recurring finding across immature programmes is a broken or unevidenced traceability chain, more often than a missing document.

Frequently asked questions

What does TARA stand for in ISO/SAE 21434?

TARA stands for threat analysis and risk assessment. It is the standard's core technical method for identifying assets, threat scenarios, attack feasibility and impact, and deriving a risk value that determines the treatment and cybersecurity requirements needed.

How does ISO/SAE 21434 relate to UN Regulation No. 155?

UN Regulation No. 155 requires vehicle manufacturers in many markets to operate a certified cybersecurity management system as a condition of type approval. ISO/SAE 21434 is widely used as the technical standard demonstrating how that management system and its engineering processes operate, though the two are formally separate instruments.

What is a Cybersecurity Assurance Level (CAL)?

A CAL is a rating, derived from the TARA's risk assessment, indicating the rigour required for the cybersecurity requirements and verification activities associated with a cybersecurity goal, conceptually similar to how ASIL drives rigour in ISO 26262.

Does ISO/SAE 21434 replace ISO 26262?

No. ISO/SAE 21434 addresses cybersecurity engineering, while ISO 26262 addresses functional safety arising from malfunctioning behaviour. Both apply to modern vehicle E/E systems, and organisations need to coordinate the two where a security compromise could create a safety hazard.

Does ISO/SAE 21434 cover post-production monitoring?

Yes. The standard requires ongoing monitoring for new cybersecurity information, vulnerabilities and incidents affecting vehicles in operation, feeding back into risk assessment and response processes, comparable in intent to vulnerability handling obligations in other product security regimes.