TARA Risk Calculator per ISO/SAE 21434
Rate a threat scenario the way ISO/SAE 21434 does: impact in four categories, attack feasibility from attack potential, and the risk value 1 to 5 with a treatment hint.
Updated This page as Markdown
In short
This calculator walks through the risk determination of ISO/SAE 21434 clause 15 for one threat scenario: you rate the damage in the safety, financial, operational and privacy categories, rate the attack feasibility with the attack potential method (elapsed time, expertise, knowledge of the item, window of opportunity, equipment, Annex G), and get the risk value from 1 to 5 per the matrix in Annex H, with a hint on the treatment decision. It runs in the browser; nothing is sent anywhere.
How it works
The calculator follows ISO/SAE 21434 clause 15 step by step. The impact rating (15.5) rates one damage scenario in the four categories the standard names, using the four levels severe, major, moderate and negligible; the tool takes the highest as the overall impact. The attack feasibility rating (15.7) uses the attack potential approach of Annex G: five factors with the point values the standard takes from ISO/IEC 18045 are added up, and the sum maps to high (0 to 13), medium (14 to 19), low (20 to 24) or very low (25 and above). The risk value (15.8) then comes from the matrix in Annex H, Table H.8, which combines overall impact and feasibility into a value from 1 to 5.
How to read the result
The risk value is an input to the treatment decision (15.9), not a verdict. What matters in an audit is that the inputs are traceable: which damage scenario, which attack path, why each factor was rated as it was. Rate the easiest attack path you know, not the average one, and revisit the rating when a test changes the facts. A SecurityAccess bypass found on the bench, for example, moves “knowledge of the item” from confidential to public and “equipment” from specialised to standard, which can turn a medium feasibility into a high one and a risk of 3 into a 5.
Limits
The tool rates one scenario with the standard’s default method and the conservative aggregation. It does not cover asset identification, threat scenario identification or attack path analysis (15.3 to 15.6), and it cannot know your organisation’s acceptance criteria. OEM-specific methods differ in weights and thresholds; follow your customer’s TARA template where one exists. AutoST feeds the attack feasibility side of this with test results: a confirmed finding is evidence for the rating.
FAQ
Frequently asked questions
Is the attack potential method mandatory?
No. ISO/SAE 21434 requires an attack feasibility rating but lets you choose the method: attack potential, CVSS-based, or attack vector based. Attack potential is the most common in TARAs we see because it maps to ISO/IEC 18045 and gives a traceable sum. The thresholds (high up to 13, medium 14 to 19, low 20 to 24, very low from 25) are the ones in Annex G.
How do the four impact categories combine?
The standard rates each category separately and leaves the aggregation to the organisation. The usual and conservative choice, which this tool uses, is to take the highest category as the overall impact. Some OEMs weight the categories or require safety to dominate; adapt to your customer’s method.
What does the risk value decide?
The treatment: avoid, reduce, share or retain the risk (clause 15.9). Values of 4 and 5 are normally reduced with cybersecurity goals and controls; 1 is typically retained with a rationale; 2 and 3 depend on your organisation’s acceptance criteria, which must be documented in the cybersecurity plan.
Sources
Related pages
- GlossaryTARA (Threat Analysis and Risk Assessment)TARA is the threat analysis and risk assessment of ISO/SAE 21434 clause 15: assets, threat scenarios, impact, attack paths, feasibility, risk value and treatment.
- GlossaryISO/SAE 21434ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles: processes, TARA, concept, development, validation. Structure and testing clauses.
- GlossaryCAL (Cybersecurity Assurance Level)The Cybersecurity Assurance Level (CAL 1 to 4) of ISO/SAE 21434 Annex E sets how rigorous verification and validation must be. How it is derived and used in testing.
- GlossaryUN R155 (UN Regulation No. 155, Cyber Security)UN R155 is the UNECE regulation that makes a certified CSMS and cyber security measures a condition for vehicle type approval. What it requires and what testers deliver.
- PlatformEvidence for your 21434 work, on tap.How AutoST supports ISO/SAE 21434 and UN R155: fuzzing and vulnerability analysis for [RC-10-12], penetration-test evidence for [RQ-11-01], plus traceable reports.
- PlatformA number you can defend, evidence you can file.AutoST scores ECU risk from 26 weighted UDS services on a 0-10 scale and produces PDF test evidence with a non-repudiation footer, plus SARIF, CSV and JSON export.
