The TARA table gathers all elements that have been modeled in the previous steps and gives a global overview of the threat scenario that has to be mitigated, retained, shared, or avoided. The risk value is automatically calculated according to the ISO/SAE 21434:2021 standard.
Cybersecurity Risk
An effect of uncertainty on road vehicle cybersecurity expressed in terms of attack feasibility and impact.
Cybersecurity Control
A measure that is modifying risk.
Cybersecurity Claim
A statement about a risk.
Cybersecurity Goal
A concept-level cybersecurity requirement associated with one or more threat scenarios.
If you create a new project using the ISO 21434 Project template, then a TARA table already exists in the 1.4 Risk Treatment and Cybersecurity Control package. |
To create a TARA Table
To add Threat Scenarios to the TARA Table
A row is added to the TARA Table, which shows the existing Threat Scenario.
|
To assign Risk Treatment Decision
Double-click the cell in the Risk Treatment Decision column and the required Threat Scenario's row. From the drop-down list, assign Risk Treatment Decision.
The Risk Treatment Decision is assigned in the TARA Table.
If the risk treatment decision is Retain, adding a claim is mandatory. In those cases, the cybersecurity goals and controls are not required. |
To add a Cybersecurity Goal to the TARA Table
|
To Generate/Synchronize the Cybersecurity Goals to the TARA Table
|
To add Controls to the TARA Table
From the Select Elements dialog, select Controls.
The Controls are added to the TARA Table.
Controls are a list of Cybersecurity Requirements. There are 4 types of Cybersecurity Requirements: Functional, Technical, Hardware, and Software. |
To ease the process of adding controls, the plugin provides a feature to add the controls with the aid of the Recommend Control command. The controls are recommended on the basis of assigned cybersecurity goals and CWE elements used as attack path steps.
To add controls using the Recommend Control command to the TARA Table
From the Select Elements dialog, select or remove the recommended controls.
For requirements to be reflected as recommended controls in the Select Elements dialog, either of these conditions should be satisfied:
|
The recommended controls are added to the TARA Table.
To add a Claim to the TARA Table
Double-click the cell in the Claims column and the required Threat Scenario's row and type in the necessary Claim.
If the risk treatment decision is Retain, adding a claim is mandatory. In those cases, the cybersecurity goals and controls are not required and cannot be specified. |
Due to some performance reason, the claim does not appear in the containment tree directly after specifying it in the claim's cell. You must save the project to see the claims in the containment tree under the smart package 2.3 Cybersecurity Claims. |
TARA Table Example
|