TARA (Threat Analysis and Risk Assessment)
TARA (Threat Analysis and Risk Assessment) is the threat analysis and risk assessment method of ISO/SAE 21434. It systematically determines which assets of a vehicle or component need protection, how an attacker could compromise them, how severe the damage would be and how the risks are treated. Important for context: a TARA is not a list of identified threats, but a traceable record of risk decisions.
A detailed introduction with practical examples — including the question of when a spreadsheet is no longer enough — is provided by our in-depth article on the TARA (in German).
The four steps of a TARA
- Item definition: define what is being considered — the item with its functions, components, channels and data flows, plus assumptions and the system boundary.
- Asset identification & impact rating: identify assets to which a security property is attached (confidentiality, integrity, availability), derive damage scenarios and rate the Impact Level (IL) — for example across safety, financial, operational and privacy consequences.
- Threat analysis: derive threat scenarios and attack steps and rate the feasibility of each attack — the result is the Attack Feasibility Level (AFL) according to the methodology of the standard.
- Determine risks: impact and attack feasibility combine via a defined risk matrix into the Risk Level (RL). For each risk, a treatment decision is made: reduce, avoid, share or accept — each with a rationale.
Introduced measures are themselves new assets: a TARA is iterative and is repeated until the residual risk is acceptable.
Context: ISO/SAE 21434 and UNECE R155
The TARA sits in the concept phase of ISO/SAE 21434 (Clause 9) and is the primary technical evidence for type approval under UNECE R155: without a solid TARA there is no demonstrated Cybersecurity Management System (CSMS) — and thus no market access in the affected markets. Beyond automotive, the same methodology supports the cyber risk assessment that the EU Cyber Resilience Act requires for products with digital elements.
TARA in practice
The TARA is a living document (see Living TARA): new vulnerabilities and attack techniques require a re-evaluation of existing decisions, which is why the original rationale must be documented and retrievable. For the first steps, a spreadsheet is sufficient — but it quickly reaches its limits with scale, changes and consistency across many attack paths. What this transition looks like is described in detail in the article on the TARA (in German).


