Article details
- Category
- Whitepaper
- Published
- Reading time
- 18 min read
- Author
- AutoSec Academy · Practitioner Editorial Team
Threat Analysis and Risk Assessment is the analytical core of ISO/SAE 21434. Done well, it directs engineering effort at the risks that matter. Done poorly, it produces a spreadsheet nobody reads and an assessor cannot verify.
Start with boundaries, not threats
The most expensive TARA mistake is beginning with a threat brainstorm. Without a settled item definition — boundaries, interfaces, operational environment and explicit assumptions — the analysis has no scope, and every review adds threats rather than resolving them.
The four failure modes
- Unbounded scope: no item definition, so the assessment never converges
- Asset inflation: every signal treated as an asset, diluting the analysis until nothing is prioritised
- Feasibility drift: ratings assigned by different engineers using different mental models of “elapsed time” and “expertise”
- Orphaned goals: cybersecurity goals derived but never traced into requirements or design
Evidence that closes findings
An assessor is testing whether the conclusion follows from the analysis. Retain the reasoning, not just the result: why an attack path was judged infeasible, what assumption underpins a control, and what would invalidate it. Assumptions that are written down can be re-tested when the design changes; assumptions held in someone’s head cannot.
A TARA is not a document you produce for an assessor. It is the record of a decision you can still defend two years later, when the engineer who made it has moved on.