Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryAutomotiveRisk

TARA (Threat Analysis and Risk Assessment)

TARA is the risk analysis method of ISO/SAE 21434 for vehicles and ECUs. The seven steps, how impact and attack feasibility are rated, and what a usable TARA looks like.

Updated This page as Markdown

In short

A TARA (Threat Analysis and Risk Assessment) identifies the assets of a vehicle component, the damage scenarios and threat scenarios against them, the attack paths, and rates impact and attack feasibility to arrive at a risk value and a treatment decision. ISO/SAE 21434:2021 defines the method in Clause 15; UN R155 requires the result as evidence for type approval. It is the central work product of automotive cybersecurity engineering.

What is a TARA?

A TARA is a structured analysis that answers, for one vehicle component or system, which assets an attacker could go after, what damage that would cause, how feasible the attack is, and what you decide to do about it. The result is a table of risks with a risk value from 1 to 5 and a treatment decision for each: avoid, reduce, share or retain.

ISO/SAE 21434 breaks the method into steps: asset identification (15.3), threat scenario identification (15.4), impact rating (15.5), attack path analysis (15.6), attack feasibility rating (15.7), risk value determination (15.8) and risk treatment decision (15.9). Impact is rated in four categories, safety, financial, operational and privacy, each as severe, major, moderate or negligible. Attack feasibility can be rated by attack potential (time, expertise, knowledge of the item, window of opportunity, equipment), by a CVSS-based approach or by attack vector.

Where is it defined?

Clause 15 of ISO/SAE 21434:2021 defines the method; Annex H gives a worked example on a headlamp system. Clause 9 (concept phase) is where the TARA is first applied: it needs an item definition (9.3) as input and produces the cybersecurity goals (9.4) and the cybersecurity concept (9.5) as output. UN Regulation No. 155 does not use the word TARA, but paragraph 7.3.3 requires the manufacturer to identify and manage the risks of the vehicle type, and Annex 5 lists the threats and mitigations the analysis is expected to consider. The TARA is how everyone meets that requirement.

What it means in practice

A TARA is only useful if it drives decisions. The versions that work share a few properties. The item definition is precise: interfaces, trust boundaries, which functions run where. Damage scenarios are written from the perspective of the road user, not the engineer (“vehicle brakes without driver input” rather than “CAN message spoofed”). Attack paths are concrete enough to be tested later. And every “reduce” decision points to a cybersecurity requirement that lands in the specification.

When we produce a TARA for a Tier-1, say for an ADAS component or an on-board charger, the hard part is calibration. Teams rate the same attack as “high” and “very low” feasibility depending on who is in the room. We settle this with a written rating guide, with the attack potential parameters filled in for typical steps (CAN injection via OBD, UDS without authentication, flash readout via debug port), and with reference to what we actually achieved in comparable penetration tests. That gives a TARA the OEM can review without re-doing it.

Common misunderstandings

A TARA is not a one-time deliverable. ISO/SAE 21434 Clause 8 expects it to be kept current as vulnerabilities, attack techniques and the product change; UN R155 paragraph 7.2.2.2 (f) demands the same. A TARA with 200 rows that nobody reads is also not a good TARA: a shorter one with traceable requirements and test cases is worth more at the audit and in the product.

FAQ

Frequently asked questions

How is a TARA different from threat modeling?

A TARA is threat modeling with a prescribed structure and output. ISO/SAE 21434 fixes the steps, the four impact categories, the rating scales and the fact that every risk needs a documented treatment decision. Generic threat modeling (STRIDE, attack trees) is freer and is often used inside a TARA to find the threat scenarios.

How long does a TARA take?

For a single ECU with a handful of interfaces, a first complete TARA typically takes a few weeks of effort spread over workshops with the system, software and hardware leads. The time goes into the item definition and into agreeing the impact ratings, not into filling the table. Updates after design changes are much faster when the first version is well structured.

Does a TARA replace a penetration test?

No. The TARA says which attacks are plausible and how bad they would be; the penetration test checks whether the controls you chose actually stop them. ISO/SAE 21434 wants both: analysis in the concept phase (Clause 9) and validation on the real product (Clause 11). We regularly find that the TARA assumed a control that the firmware never implemented.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab