MoRA (Modular Risk Assessment)
MoRA (Modular Risk Assessment) is a methodology for security risk analyses developed at Fraunhofer AISEC (Fraunhofer Institute for Applied and Integrated Security). It structures the analysis in a model-based and modular way and is one of the established methodologies with which a Threat Analysis and Risk Assessment (TARA) according to ISO/SAE 21434 can be carried out in practice.
The Four Phases
MoRA structures the risk analysis into four consecutive phases:
- Model the system: The data about the system under evaluation is collected and captured as a model — with functions, components, data and data flows as modelling entities. This corresponds to the Item Definition of ISO/SAE 21434.
- Identify protection needs: Security attributes such as confidentiality, integrity and availability are attached to the system elements. This yields security goals whose damage potential is evaluated via damage criteria such as safety and financial consequences.
- Analyse threats: Known threats are evaluated against the system elements — for example based on catalogues — and rated via risk factors such as time, access, knowledge and equipment.
- Analyse risks: Using the system model, it is calculated how security goals are threatened; from damage potential and attack effort, the risk level of each risk results via propagation.
Why Modular?
The eponymous principle is the clear separation of the building blocks, in particular of impact assessment and threat assessment. It ensures that the method scales with the status of the development process: the protection needs can already be assessed in the design phase, before implementation details are fixed, and the threat landscape can be updated later without touching the protection needs analysis. At the same time, building blocks such as threat catalogues and rating schemes become reusable across projects.
MoRA in Practice
Tool-supported workflows inspired by MoRA — for example in itemis SECURE — implement the four phases as linked model elements, so that rating changes propagate automatically along the links. How such a TARA works in detail is described in our article on the TARA; the normative framework is provided by the cyber security spoke page.


