Skip to main content

MoRA (Modular Risk Assessment)

MoRA (Modular Risk Assessment) is a methodology for security risk analyses developed at Fraunhofer AISEC (Fraunhofer Institute for Applied and Integrated Security). It structures the analysis in a model-based and modular way and is one of the established methodologies with which a Threat Analysis and Risk Assessment (TARA) according to ISO/SAE 21434 can be carried out in practice.

The Four Phases

MoRA structures the risk analysis into four consecutive phases:

  • Model the system: The data about the system under evaluation is collected and captured as a model — with functions, components, data and data flows as modelling entities. This corresponds to the Item Definition of ISO/SAE 21434.
  • Identify protection needs: Security attributes such as confidentiality, integrity and availability are attached to the system elements. This yields security goals whose damage potential is evaluated via damage criteria such as safety and financial consequences.
  • Analyse threats: Known threats are evaluated against the system elements — for example based on catalogues — and rated via risk factors such as time, access, knowledge and equipment.
  • Analyse risks: Using the system model, it is calculated how security goals are threatened; from damage potential and attack effort, the risk level of each risk results via propagation.

Why Modular?

The eponymous principle is the clear separation of the building blocks, in particular of impact assessment and threat assessment. It ensures that the method scales with the status of the development process: the protection needs can already be assessed in the design phase, before implementation details are fixed, and the threat landscape can be updated later without touching the protection needs analysis. At the same time, building blocks such as threat catalogues and rating schemes become reusable across projects.

MoRA in Practice

Tool-supported workflows inspired by MoRA — for example in itemis SECURE — implement the four phases as linked model elements, so that rating changes propagate automatically along the links. How such a TARA works in detail is described in our article on the TARA; the normative framework is provided by the cyber security spoke page.

Related terms

Frequently asked questions

Is MoRA the same as a TARA?
No. TARA denotes the normatively required process of ISO/SAE 21434 including its work products; MoRA is a concrete methodology with which this process can be carried out. The standard does not mandate any particular method — MoRA is one of the established answers to the question of how to build a TARA in practice.
What does "modular" mean in MoRA?
The clear separation of the analysis building blocks: system model, protection needs, threats and risks are independent, linked modules. In particular, the separation of impact assessment and threat assessment ensures that the analysis scales with the status of the development process and that building blocks can be reused.
What role does MoRA play in itemis SECURE?
The TARA workflow of itemis SECURE is inspired by MoRA: system model, protection needs, threat and risk analysis are implemented as linked model elements, and the risk calculation propagates along these links. Other risk assessment methods from academia and industry can be realised with it as well.
Reviewed by Jens Bühl, Product Owner on August 21, 2026