ISO/SAE 21434 TARA
Automated CAL 1–4
Attack Trees
Damage Scenarios
Client ECU
Review Lifecycle

AutoSec360Built for Automotive TARA.

Perform, review, and sign off Vehicle electronics systems risk assessments in one governed workspace.

TOTAL ASSETS
0
DAMAGE SCENARIOS📈
0
ATTACK PATHS🎯
0
SECURITY GOALS🛡️
0
📊Risk Score Distribution
375 paths
Score 1
Score 2
Score 3
Score 4
0
Score 4
Total0
Impact Level Distribution
45 scenarios
Severe
Major
Moderate
Negligible
0
Major
Total0
🎯Attack Feasibility Distribution
375 paths
Very Low
Low
Medium
High
0
Low
Total0
🛰️Attack Vector Distribution
45 scenarios
Physical
Local
Adjacent
Network
0
Physical
Total0
375 Attack Paths Mapped
CAL 4 Risk Level Computed
ISO 21434 Audit Trail Ready

What is TARA?Threat Analysis and Risk Assessment.

TARA (Threat Analysis and Risk Assessment) is the standardized engineering methodology mandated by ISO/SAE 21434 and UNECE R155. It systematically identifies vehicle electronic assets, uncovers potential cyber attack paths, calculates damage impact to road users (SFOP), and assigns Cybersecurity Assurance Levels (CAL 1–4) to secure modern automotive architectures.

Automated Asset & Threat Identification

Systematically map ECU electronic assets, trust boundaries, and multi-bus interfaces to identify potential threat scenarios without cataloging bottlenecks.

Rigorous Attack Feasibility & CAL Scoring

Evaluate attack feasibility across time, expertise, and equipment parameters to quantify road-user impact and compute CAL 1–4 risk levels with precision.

Governed Review & Compliance Sign-Off

Empower engineering leads with field-level reviews, immutable audit trails, and 1-click compliance dossiers built for UNECE R155 type approvals.

Meet the features

The collaborative platform for automotive TARA, built around ISO/SAE 21434. Replace disconnected spreadsheets with automated calculations, reusable baseline ECUs, and governed multi-role sign-offs.

Review Life Cycle

Each TARA moves through a formal Draft → Pending Review → On Review → Approved lifecycle with role-based responsibilities. Authors edit in Draft; submission enforces a strict edit-lock so reviewers assess a stable snapshot; and approvals create an immutable, tamper-evident audit trail.

Double Click Feature

Double-click any asset to immediately open its properties in place. Modify parameters, reclassify components, and commit governed changes with automatic versioning and zero context switching.

I Button Feature

Hover over any asset tag in damage scenarios to instantly reveal comprehensive technical specifications, hardware attributes, and security boundaries in an upward-expanding contextual inspector.

Attack Tree Feature

Visually model multi-step attack vectors and exploit feasibility down to individual hardware interfaces, evaluating successful versus blocked paths for ISO/SAE 21434 threat assessment.

Live Risk Calculation

Instantly recalculate cybersecurity assurance levels (CAL) and overall risk ratings in real-time as damage scenarios, safety parameters, or attack vectors change, maintaining full ISO/SAE 21434 Annex E compliance.

01 / 05

Advanced Telematics Unit
DRAFT
TARA ANALYSIS
v1.9
2 open
Author
Advanced Telematics Unit
PENDING
TARA ANALYSIS
v1.9
2 open
Reviewer
Advanced Telematics Unit
PENDING
TARA ANALYSIS
v1.9
2 open
Conf. Reviewer
Advanced Telematics Unit
PENDING
TARA ANALYSIS
v1.9
2 open
Approver
Report approved
AST-01
MCU (MIMXRT1064)
ASSET TYPE
Hardware
DESCRIPTION

Main processing unit of the telematics device responsible for executing application firmware, handling communication protocols, processing GPS data, and managing peripheral interfaces. Other ECU firmware update via CAN

FEATURES

High-performance ARM Cortex-M7, real-time processing, peripheral interface control, memory management, interrupt handling.

DAMAGE SCENARIOS
1
ATTACK PATHS
9
RISK SCORE
5
CAL LEVEL
CAL 3
Editing: unsaved changes
DS-01MCU (MIMXRT1064)
ConfidentialityIntegrityAvailability
DAMAGE SCENARIO (15.3)

Unauthorized execution of malicious or modified firmware on the MCU due to lack of secure boot or validation, leading to complete compromise of device functionality, control logic, and communication interfaces.

ATTACK PATH

AP-1

Classification:Tampering Elevation of Privilege
Interface:RS232 Debug Port
STEP 1[Attack Successful]

To Perform RS232 Debug Port Exploitation Attack

STEP 1[Attack Blocked]

To Perform RS232 Debug Port Exploitation Attack

STEP 2[Attack Successful]

Identify and access exposed RS232 debug interface.

STEP 2[Attack Blocked]

Identify and access exposed RS232 debug interface.

Editing: unsaved changes
DS-01

MCU (MIMXRT1064)

Unauthorized execution of malicious or modified firmware on the MCU due to lack of secure boot or validation, leading to complete compromise of device functionality, control logic, and communication interfaces.
✓ Confidentiality✓ Integrity✓ Availability
SAFETY
None
Severe
Major
Moderate
Negligible
PRIVACY
Moderate
FINANCIAL
Negligible
OPERATIONAL
Moderate
FINAL RATING
Moderate
Compromise of MCU enables full control over device logic and communication behavior. This can disrupt trusted operations and influence safety-related decisions indirectly.
ATTACK VECTOR
None
Physical
Local
Adjacent
Network
MEDIUM OF ATTACK
MCU
THREAT TYPE
Spoofing / Tampering
CAL LEVEL
CAL1
Updated successfully
Feature 01Review Life Cycle

Each TARA moves through a formal Draft → Pending Review → On Review → Approved lifecycle with role-based responsibilities. Authors edit in Draft; submission enforces a strict edit-lock so reviewers assess a stable snapshot; and approvals create an immutable, tamper-evident audit trail.

01 / 05

AutoSec360 vs. Other Approaches

How AutoSec360 Fills the Gaps

CategoryPurposeExampleCapabilities
SpreadsheetsAd-hoc data entry & manual calculationsExcel, Google SheetsManual matrix lookups, formula errors, and no audit trail
Generic ALMTask & issue trackingJira, ConfluenceLimited to task lists without automated TARA calculations or ISO 21434 rules
Requirements ToolsStatic system specificationIBM DOORS, PolarionStatic documentation lacking threat modeling or review edit-locks
Automated TARAAutomated ISO/SAE 21434 risk assessment
AutoSec360
Automated CAL & risk calculations with an enforced audit trail

Move from disconnected spreadsheets to automated, audit-ready TARA.