Skip to main content

Living TARA (Dynamic TARA)

Living TARA (synonym: Dynamic TARA) refers to a threat analysis and risk assessment (TARA) that is kept up to date across the entire product lifecycle. New vulnerabilities, changed components and new attack techniques feed continuously into the risk assessment. The TARA is therefore not a one-off document from the concept phase, but a maintained model that reflects the current risk state of the product.

Why a TARA has to live

A TARA assesses risks based on the state of knowledge at the time of its creation. This state becomes outdated: new vulnerabilities (CVEs) become known in installed components, attack techniques evolve, and software updates change the attack surface of the product. Each of these changes can shift the attack feasibility on existing paths and thus invalidate risk decisions that have already been made.

ISO/SAE 21434 accounts for this: Clause 8 requires continual cybersecurity activities — monitoring of relevant sources, evaluation of new events and vulnerability analysis across the entire lifecycle. UNECE R155 requires the same capability at management level: the manufacturer must demonstrate that risks are identified and treated even after the start of production.

Prerequisites in practice

  • Traceable risk decisions: every assessment and its rationale must be documented and retrievable so that they can be specifically re-examined when new findings emerge.
  • Links instead of spreadsheet rows: assets, threat scenarios, attack paths and measures must exist as a connected model. Only then can the impact of a new vulnerability on concrete risk decisions be determined in an automated way.
  • Connection to vulnerability management: incoming CVE reports, findings from Coordinated Vulnerability Disclosure and component information from the SBOM must be attributable to the affected elements of the TARA.

Distinction from the classic TARA

Methodically, a Living TARA does not differ from a classic TARA — the four steps from item definition to risk treatment remain the same. The difference lies in how the result is handled: the classic view treats the TARA as an evidence document for the concept phase, while the Living TARA treats it as a continuously updated risk model against which new events are checked on an ongoing basis.

Frequently asked questions

What is the difference between Living TARA and Dynamic TARA?
None — both terms describe the same concept: a TARA that is continuously maintained after its initial creation and re-evaluated when new findings emerge. Which term is used is a matter of convention within the respective organisation.
Does ISO/SAE 21434 require a Living TARA?
The standard does not use the term, but it requires exactly that: Clause 8 demands continual cybersecurity activities such as monitoring, evaluation of new events and vulnerability analysis across the entire lifecycle. A TARA that is never touched again after the concept phase does not meet this requirement.
Why is a spreadsheet not enough for a Living TARA?
For every new vulnerability, it must be checked which attack paths and risk decisions are affected. In a spreadsheet, this means manual searching across many rows and sheets, with no visibility of dependencies. A model that links assets, attack paths and measures makes the impact of a change directly traceable.

Related terms

Reviewed by Dirk Leopold, Executive Vice President Digital Engineering on July 20, 2026