The TARA (Threat Analysis and Risk Assessment) process is described in Chapter 15 of ISO/SAE 21434:2021. It is a methodology used to identify and assess cyber security threats and vulnerabilities beginning with the design phase of a product.
The following is the standard procedure followed in TARA:
An Item is a part of the system architecture to be protected. An Item with a Functional Cybersecurity Concept (output of the study) is the system architecture with additional requirements and claims that ensures a secure system. |