Skip to main content

Whitepaper

A Defensible TARA: Method, Evidence and Common Failure Modes

A practitioner whitepaper on running Threat Analysis and Risk Assessment so the result survives independent review — including the four failure modes we see most often.

Article details

Category
Whitepaper
Published
Reading time
18 min read
Author
AutoSec Academy · Practitioner Editorial Team

Threat Analysis and Risk Assessment is the analytical core of ISO/SAE 21434. Done well, it directs engineering effort at the risks that matter. Done poorly, it produces a spreadsheet nobody reads and an assessor cannot verify.

Start with boundaries, not threats

The most expensive TARA mistake is beginning with a threat brainstorm. Without a settled item definition — boundaries, interfaces, operational environment and explicit assumptions — the analysis has no scope, and every review adds threats rather than resolving them.

The four failure modes

  1. Unbounded scope: no item definition, so the assessment never converges
  2. Asset inflation: every signal treated as an asset, diluting the analysis until nothing is prioritised
  3. Feasibility drift: ratings assigned by different engineers using different mental models of “elapsed time” and “expertise”
  4. Orphaned goals: cybersecurity goals derived but never traced into requirements or design

Evidence that closes findings

An assessor is testing whether the conclusion follows from the analysis. Retain the reasoning, not just the result: why an attack path was judged infeasible, what assumption underpins a control, and what would invalidate it. Assumptions that are written down can be re-tested when the design changes; assumptions held in someone’s head cannot.

A TARA is not a document you produce for an assessor. It is the record of a decision you can still defend two years later, when the engineer who made it has moved on.

Back to the Knowledge Center

Stay current

Get the Next One in Your Inbox

Regulatory updates and lab research, sent when there is something worth saying.

Threat intelligence, straight to your inbox

Regulatory updates, lab research and new program announcements. No noise.

What should we send you?

Go Deeper Than an Article

The programs behind this analysis put you on real ECU hardware, with practitioners who do this work for a living.