The fundamentals of performing an effective TARA
In Chapter 5, we introduced some of the basic tenets of the ISO/SAE 21434 threat modeling approach. But even when following the ISO methodology, it is not uncommon to execute the TARA poorly, producing sub-optimal analysis results while exceeding the allotted time for analysis. It is not uncommon for teams to spend so much time performing the TARA that it makes it impossible to incorporate the risk mitigations within a given project schedule. As we dive deeper into the practical aspects of a TARA, we will keep this in mind to ensure that we are not simply going through the motions of performing the TARA but rather producing a valuable output within a reasonable time frame to elevate the security bar of our automotive systems. But first, let’s review some of the basic terms and definitions that will be repeatedly referenced throughout this chapter.
Assets
ISO/SAE 21434 defines an asset as “an object that has value...