Skip to main content

Item Definition

The Item Definition is the first step of the Threat Analysis and Risk Assessment (TARA) according to ISO/SAE 21434 and its only normative prerequisite. It defines what is analysed: the item — a system or combination of components that implements a function at vehicle level — with its functions, its preliminary architecture and the item boundary, i.e. the border to its environment. In addition, it documents the cybersecurity-relevant conditions and assumptions the analysis relies on.

What Belongs in an Item Definition

The standard requires exactly three things at this point: the item boundary, the functions of the item and a preliminary architecture. The boundary is described via the interfaces to other items in the vehicle and to systems outside. The preliminary architecture describes the inner structure: which components the item consists of, how they are connected, which data flows and is stored, and which interfaces lead outside. In a model-based approach, it is described via five element types: functions, components, channels, data flows and data.

Why the Standard Starts There

Every subsequent TARA step builds on the Item Definition: assets are elements of the item, threat scenarios violate security properties of these assets, and attack paths run along the channels and interfaces the architecture describes. The verification of the analysis also explicitly checks its completeness against the Item Definition. Completeness can only be measured against a defined item; measured against a blurry item, every analysis is “complete”.

The Item Definition in Practice

The preliminary architecture is exactly that: preliminary. In the course of development, it is replaced by the actual architecture, and each of these replacements affects the assets, threat scenarios and attack paths built on top of it. A static Item Definition therefore quickly decouples from engineering reality, and every downstream TARA result silently inherits this drift. For audit-ready analyses according to ISO/SAE 21434, a living model that stays in sync with the leading engineering artefacts proves its worth. Why this step decides the quality of the whole TARA is described in our in-depth article on the Item Definition.

Related terms

Frequently asked questions

What does ISO/SAE 21434 require for the Item Definition?
Exactly three things: the item boundary, i.e. the border between the item and its environment, the functions of the item and a preliminary architecture. In addition, the cybersecurity-relevant conditions and assumptions the analysis relies on — for example that a PKI certification authority the item depends on is operated properly.
How detailed does an Item Definition have to be?
Detailed enough to carry the analysis, but not a copy of the E/E architecture. A proven test question: a detail belongs in the Item Definition if it can change an asset, a threat scenario, an attack path or a rating. The lower bound is set by vulnerability management: the components must be cut finely enough that SBOM entries can attach to them.
What is an item in the sense of the standard?
A system or a combination of systems that implements a function at vehicle level — for example a braking system or a telematics unit. The item boundary separates the item from other items in the vehicle and from systems outside, described via its interfaces.
Reviewed by Jens Bühl, Product Owner on August 21, 2026