TARA (Threat Analysis and Risk Assessment)
TARA is the risk analysis method of ISO/SAE 21434 for vehicles and ECUs. The seven steps, how impact and attack feasibility are rated, and what a usable TARA looks like.
Updated This page as Markdown
In short
A TARA (Threat Analysis and Risk Assessment) identifies the assets of a vehicle component, the damage scenarios and threat scenarios against them, the attack paths, and rates impact and attack feasibility to arrive at a risk value and a treatment decision. ISO/SAE 21434:2021 defines the method in Clause 15; UN R155 requires the result as evidence for type approval. It is the central work product of automotive cybersecurity engineering.
What is a TARA?
A TARA is a structured analysis that answers, for one vehicle component or system, which assets an attacker could go after, what damage that would cause, how feasible the attack is, and what you decide to do about it. The result is a table of risks with a risk value from 1 to 5 and a treatment decision for each: avoid, reduce, share or retain.
ISO/SAE 21434 breaks the method into steps: asset identification (15.3), threat scenario identification (15.4), impact rating (15.5), attack path analysis (15.6), attack feasibility rating (15.7), risk value determination (15.8) and risk treatment decision (15.9). Impact is rated in four categories, safety, financial, operational and privacy, each as severe, major, moderate or negligible. Attack feasibility can be rated by attack potential (time, expertise, knowledge of the item, window of opportunity, equipment), by a CVSS-based approach or by attack vector.
Where is it defined?
Clause 15 of ISO/SAE 21434:2021 defines the method; Annex H gives a worked example on a headlamp system. Clause 9 (concept phase) is where the TARA is first applied: it needs an item definition (9.3) as input and produces the cybersecurity goals (9.4) and the cybersecurity concept (9.5) as output. UN Regulation No. 155 does not use the word TARA, but paragraph 7.3.3 requires the manufacturer to identify and manage the risks of the vehicle type, and Annex 5 lists the threats and mitigations the analysis is expected to consider. The TARA is how everyone meets that requirement.
What it means in practice
A TARA is only useful if it drives decisions. The versions that work share a few properties. The item definition is precise: interfaces, trust boundaries, which functions run where. Damage scenarios are written from the perspective of the road user, not the engineer (“vehicle brakes without driver input” rather than “CAN message spoofed”). Attack paths are concrete enough to be tested later. And every “reduce” decision points to a cybersecurity requirement that lands in the specification.
When we produce a TARA for a Tier-1, say for an ADAS component or an on-board charger, the hard part is calibration. Teams rate the same attack as “high” and “very low” feasibility depending on who is in the room. We settle this with a written rating guide, with the attack potential parameters filled in for typical steps (CAN injection via OBD, UDS without authentication, flash readout via debug port), and with reference to what we actually achieved in comparable penetration tests. That gives a TARA the OEM can review without re-doing it.
Common misunderstandings
A TARA is not a one-time deliverable. ISO/SAE 21434 Clause 8 expects it to be kept current as vulnerabilities, attack techniques and the product change; UN R155 paragraph 7.2.2.2 (f) demands the same. A TARA with 200 rows that nobody reads is also not a good TARA: a shorter one with traceable requirements and test cases is worth more at the audit and in the product.
FAQ
Frequently asked questions
How is a TARA different from threat modeling?
A TARA is threat modeling with a prescribed structure and output. ISO/SAE 21434 fixes the steps, the four impact categories, the rating scales and the fact that every risk needs a documented treatment decision. Generic threat modeling (STRIDE, attack trees) is freer and is often used inside a TARA to find the threat scenarios.
How long does a TARA take?
For a single ECU with a handful of interfaces, a first complete TARA typically takes a few weeks of effort spread over workshops with the system, software and hardware leads. The time goes into the item definition and into agreeing the impact ratings, not into filling the table. Updates after design changes are much faster when the first version is well structured.
Does a TARA replace a penetration test?
No. The TARA says which attacks are plausible and how bad they would be; the penetration test checks whether the controls you chose actually stop them. ISO/SAE 21434 wants both: analysis in the concept phase (Clause 9) and validation on the real product (Clause 11). We regularly find that the TARA assumed a control that the firmware never implemented.
Sources
Related pages
- GlossaryISO/SAE 21434ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles. Its clauses, how it relates to UN R155, and what it asks from OEMs and suppliers.
- GlossaryThreat ModelingThreat modeling is the structured search for what can go wrong in a system before it is built. The four questions, STRIDE and attack trees, and how it feeds a pentest.
- GlossaryCSMS (Cybersecurity Management System)A CSMS is the organisational process framework UN R155 requires from vehicle manufacturers. What it must cover, how it is audited, and what suppliers deliver to it.
- InsightsISO/SAE 21434 vs UN R155: How They Fit TogetherUN R155 is the law, ISO/SAE 21434 is the engineering standard. Learn how CSMS, TARA and testing connect, and what suppliers need to deliver to OEMs.
- ServicesISO/SAE 21434 that survives the audit and the attacker.ISO/SAE 21434 consulting by certified experts: gap analysis, CSMS implementation, TARA, verification and audit preparation for UN R155. With real testing.
