Skip to main content
Hands-on lab
Compliance
Validation
Leader

AutoSec TARA Lab

Model threats against real vehicle architectures

Run end-to-end Threat Analysis and Risk Assessment on production-representative E/E architectures. Build item definitions, derive attack paths and defend your risk ratings in review.

Primary objectives

  1. Define items and assets from a real vehicle architecture
  2. Derive attack paths and rate feasibility
  3. Produce cybersecurity goals and requirements
  4. Defend a TARA in a simulated assessment review

Overview

What This Lab Is For

The TARA Lab exists because risk assessment is a skill that only develops against real complexity. Participants work on production-representative E/E architectures — a central gateway with diagnostic and OTA interfaces, a telematics unit with three wireless entry points — and defend their conclusions in a review modelled on an actual assessment.

Run end-to-end Threat Analysis and Risk Assessment on production-representative E/E architectures. Build item definitions, derive attack paths and defend your risk ratings in review.

Learning goals

  • Produce audit-ready TARA documentation
  • Justify risk treatment decisions to assessors

Technology stack

  • ISO/SAE 21434
  • UNECE R155
  • CVSS
  • Attack trees

Tools used

Hardware, Software and Security Tooling

Production-representative equipment and the toolchains engineers use on the job — not simulators standing in for them.

  • Hardware

    Physical targets and instrumentation you will work on directly.

    • Domain gateway ECURepresentative central gateway with diagnostic and OTA interfaces
    • Telematics control unitCellular, Bluetooth and Wi-Fi attack surface
    • CAN logger and bus interfaceBus interface
  • Security tools

    Analysis, testing and cryptographic tooling applied to the targets.

    • Threat modelling workbench
    • Attack path analyser
    • Risk rating calculator

Exercises

2 Assessed Exercises

Each exercise is assessed rather than demonstrated. Durations are indicative and vary with cohort experience.

  1. Central gateway TARA

    intermediate

    Full assessment of a domain gateway including diagnostic and OTA interfaces.

    Duration
    4 hours
  2. Telematics unit attack paths

    advanced

    Derive and rate attack paths across cellular, Bluetooth and Wi-Fi interfaces.

    Duration
    3 hours

Learning outcomes

What You Can Demonstrate Afterwards

An at-a-glance summary — each item is expanded in the sections above and below.

Skills acquired

2

Assessed competencies, listed in full under Overview above.

Capability levels
L2 · ComplianceL4 · ValidationL6 · Leader
Programs supported

4

Listed with their capability level in the next section.

Capability framework

Where This Lab Sits in the Framework

All six levels, and this lab’s relationship to each — including the ones it deliberately does not cover.

  1. Not covered

    Level 1 · Awareness

    Cybersecurity Awareness

    Covered by other labs in the estate

  2. Supported

    Level 2 · Compliance

    Enable ISO 21434, UNECE R155/R156, AIS standards and CSMS implementation.

  3. Not covered

    Level 3 · Secure Developer

    Secure Developer

    Covered by other labs in the estate

  4. Supported

    Level 4 · Validation

    Master TARA, security validation, fuzz testing and architecture review.

  5. Not covered

    Level 5 · Offensive

    Offensive Security Expert

    Covered by other labs in the estate

  6. Supported

    Level 6 · Leader

    Lead CSMS transformation, security governance and enterprise capability programmes.

Common questions

AutoSec TARA Lab FAQ

What engineers and their managers ask before booking lab time.

Do I need my own architecture to work on?
No. The lab supplies production-representative architectures with complete item definitions. Corporate cohorts can substitute their own platform where confidentiality allows, which makes the output directly usable — but it is not a prerequisite.
Is the assessment review realistic?
It is modelled on a type-approval assessment: you present the TARA, an assessor challenges the feasibility ratings and the traceability from threat to cybersecurity goal, and you defend your reasoning. Most participants report the review as the hardest and most useful part of the lab.
What do I take away afterwards?
A completed TARA you produced yourself, the rating criteria calibrated during the exercise, and a review report identifying where your reasoning held and where it did not.

Get Your Engineers Into the AutoSec TARA Lab

Lab access is included with the programs above, and can be delivered onsite, remotely or as part of a corporate academy.