Cybersecurity Goal
A cybersecurity goal is a top-level security requirement that is identified in the concept phase of a product according to ISO/SAE 21434. Cybersecurity goals result from the risk treatment of the Threat Analysis and Risk Assessment (TARA): for risks that are to be reduced, it is recorded which security property of which assets needs to be protected. This makes them the central connecting element between assets, damage scenarios and the later cybersecurity requirements.
The Relationships of a Cybersecurity Goal
The standard positions cybersecurity goals via clearly named relationships: a goal is allocated to an item, it mitigates the risk of an asset, it addresses damage scenarios and thus indirectly the associated threat scenarios, and it is realised by cybersecurity requirements. This chain makes it traceable why a requirement exists: each one can be traced back to a risk decision.
From Goal to Control
Cybersecurity goals do not yet describe a concrete implementation. Only in the development phase are they refined via cybersecurity requirements into concrete security controls, i.e. the measures actually implemented. This is why the TARA and concept clauses of the standard do not speak of controls; they belong to product development. Important in practice: controls themselves introduce new assets whose risks must also be assessed. The analysis therefore becomes iterative and should carry the history of decisions as a single source of truth throughout the lifecycle.
Parallel to the Safety Goal
The terminology deliberately follows the safety goal of ISO 26262: both are top-level requirements from the concept phase. The difference lies in the dynamics. While safety requirements can largely be refined hierarchically in the V-model, security measures depend heavily on implementation details and change the analysis itself through their introduction. How the goals emerge from the risk assessment is described in detail by the TARA; their place in the process is shown on the cyber security spoke page.


