What is TARA?
Threat Analysis and Risk Assessment (TARA) is a structured methodology used to identify potential cyber threats to a system, evaluate associated risks, and determine appropriate countermeasures. In the automotive context, TARA is a key requirement of ISO/SAE 21434 for automotive cybersecurity engineering.
TARA Process
- Asset identification: Identify assets and their security properties
- Threat identification: Enumerate potential threats using structured methods
- Impact analysis: Assess potential consequences of successful attacks
- Attack feasibility assessment: Evaluate the likelihood and difficulty of attacks
- Risk determination: Combine impact and feasibility to determine risk levels
- Risk treatment: Select and document appropriate countermeasures
Application in Automotive
TARA is applied throughout the automotive development lifecycle, from concept through production and operations. It ensures that cybersecurity risks are systematically identified and addressed at each stage.
Standards Reference
TARA methodologies are defined in ISO/SAE 21434 (Road vehicles - Cybersecurity engineering) and referenced in UNECE WP.29 regulations for automotive cybersecurity.
Back to Glossary