Skip to main content

Cybersecurity Concept

The cybersecurity concept is the work product that concludes the concept phase of ISO/SAE 21434. It contains the cybersecurity requirements of the item and the requirements for its operational environment, each derived from the cybersecurity goals, and allocates them to the elements of the preliminary architecture. It is thus the link between risk analysis and product development: goals become located, implementable requirements.

From Goal to Concept

The chain of the concept phase runs from the Item Definition via the Threat Analysis and Risk Assessment (TARA) to the cybersecurity goals — and the cybersecurity concept turns them into requirements. Each requirement realises one or more goals and is either allocated to an element of the item or formulated as a requirement for the operational environment, for example for backend systems, production processes or workshops. This allocation is the actual design step: it decides where in the system a protective effect is provided.

Cybersecurity Claims

If a risk decision relies on assumptions about the operational environment, the standard requires documented cybersecurity claims for it — for example for shared or accepted risks. A claim is a commitment that must be monitored: if it turns out in operation that the assumption no longer holds, the associated risk decision must be re-evaluated. Undocumented assumptions are therefore non-auditable claims that simply have not been noticed yet.

The Cybersecurity Concept in Practice

The concept is not a one-off document but the current state of an ongoing derivation: if the architecture changes, allocations shift; if the TARA changes a risk rating, goals and thus requirements change. This only remains auditable if the chain from the risk decision via the goal to the allocated requirement is traceably linked instead of being copied across document boundaries. How this chain emerges in the TARA and what role it plays for analyses according to ISO/SAE 21434 is described on the linked pages.

Related terms

Frequently asked questions

What is the difference between a cybersecurity goal and the cybersecurity concept?
The goal is the individual objective, the concept the whole: it comprises the cybersecurity requirements that achieve all goals of the item and allocates them to the elements of the architecture or the operational environment. A goal describes what is to be protected; the concept describes through which requirements and at which place this happens.
What is a cybersecurity claim?
A documented assumption about the operational environment of the item on which a risk decision relies — for example that a backend only allows authorised access. Claims are mainly used for shared or accepted risks and must be monitored throughout the lifecycle: if the assumption falls, the decision falls.
When is the cybersecurity concept created?
At the end of the concept phase (Clause 9 of the standard), after the Item Definition, the TARA and the formulation of the cybersecurity goals. It is the handover point to product development, which refines the requirements into concrete specifications and security controls.
Reviewed by Jens Bühl, Product Owner on August 21, 2026