Cybersecurity Concept
The cybersecurity concept is the work product that concludes the concept phase of ISO/SAE 21434. It contains the cybersecurity requirements of the item and the requirements for its operational environment, each derived from the cybersecurity goals, and allocates them to the elements of the preliminary architecture. It is thus the link between risk analysis and product development: goals become located, implementable requirements.
From Goal to Concept
The chain of the concept phase runs from the Item Definition via the Threat Analysis and Risk Assessment (TARA) to the cybersecurity goals — and the cybersecurity concept turns them into requirements. Each requirement realises one or more goals and is either allocated to an element of the item or formulated as a requirement for the operational environment, for example for backend systems, production processes or workshops. This allocation is the actual design step: it decides where in the system a protective effect is provided.
Cybersecurity Claims
If a risk decision relies on assumptions about the operational environment, the standard requires documented cybersecurity claims for it — for example for shared or accepted risks. A claim is a commitment that must be monitored: if it turns out in operation that the assumption no longer holds, the associated risk decision must be re-evaluated. Undocumented assumptions are therefore non-auditable claims that simply have not been noticed yet.
The Cybersecurity Concept in Practice
The concept is not a one-off document but the current state of an ongoing derivation: if the architecture changes, allocations shift; if the TARA changes a risk rating, goals and thus requirements change. This only remains auditable if the chain from the risk decision via the goal to the allocated requirement is traceably linked instead of being copied across document boundaries. How this chain emerges in the TARA and what role it plays for analyses according to ISO/SAE 21434 is described on the linked pages.


