Skip to main content

Cybersecurity Goal

A cybersecurity goal is a top-level security requirement that is identified in the concept phase of a product according to ISO/SAE 21434. Cybersecurity goals result from the risk treatment of the Threat Analysis and Risk Assessment (TARA): for risks that are to be reduced, it is recorded which security property of which assets needs to be protected. This makes them the central connecting element between assets, damage scenarios and the later cybersecurity requirements.

The Relationships of a Cybersecurity Goal

The standard positions cybersecurity goals via clearly named relationships: a goal is allocated to an item, it mitigates the risk of an asset, it addresses damage scenarios and thus indirectly the associated threat scenarios, and it is realised by cybersecurity requirements. This chain makes it traceable why a requirement exists: each one can be traced back to a risk decision.

From Goal to Control

Cybersecurity goals do not yet describe a concrete implementation. Only in the development phase are they refined via cybersecurity requirements into concrete security controls, i.e. the measures actually implemented. This is why the TARA and concept clauses of the standard do not speak of controls; they belong to product development. Important in practice: controls themselves introduce new assets whose risks must also be assessed. The analysis therefore becomes iterative and should carry the history of decisions as a single source of truth throughout the lifecycle.

Parallel to the Safety Goal

The terminology deliberately follows the safety goal of ISO 26262: both are top-level requirements from the concept phase. The difference lies in the dynamics. While safety requirements can largely be refined hierarchically in the V-model, security measures depend heavily on implementation details and change the analysis itself through their introduction. How the goals emerge from the risk assessment is described in detail by the TARA; their place in the process is shown on the cyber security spoke page.

Related terms

Frequently asked questions

What is the difference between a cybersecurity goal and a security control?
The phase and the level of concreteness. Cybersecurity goals are created in the concept phase and do not yet describe a concrete implementation. Controls are artefacts of the development phase: the measures actually implemented. In between sit the cybersecurity requirements, which refine the goals step by step.
Where do cybersecurity goals come from?
From the risk treatment of the TARA. If the decision for a risk is to reduce it, a cybersecurity goal is formulated for it. It records which security property of which assets is to be protected, without anticipating the how.
Is there a parallel to the safety goal of ISO 26262?
Yes, the terminology is deliberately analogous: both are top-level requirements created in the concept phase. One important difference remains: security measures depend heavily on implementation details and introduce new assets themselves, which is why the analysis has to be updated iteratively instead of following a strictly hierarchical refinement as in the classic V-model.
Reviewed by Jens Bühl, Product Owner on August 21, 2026