Products

How to Run ISO/SAE 21434 TARA in Polarion better and faster

How to Run ISO/SAE 21434 TARA in Polarion

ISO/SAE 21434 threat analysis with automated scoring, built-in traceability, and zero spreadsheet chaos.

Every connected ECU needs a TARA. ISO/SAE 21434 says so. UN R155 says so. Your customer’s cybersecurity requirements say so.

And most teams still do it in Excel.

The spreadsheet starts clean. Three months later: 400 rows, seven frozen columns, three conflicting color schemes, and a formula that references a deleted sheet. The cybersecurity manager exports a PDF for the audit. Nobody asks what happens when a requirement changes.

There’s a better way.


Five Steps, Five Views

A TARA follows five steps. Each step gets its own view — showing only the columns that matter right now, hiding everything else.

TARA 5-step workflow: Identify, Score, Assess, Treat, Verify

1. Identify Threats

Pick a stakeholder from the catalog. Select a CIAx property. Describe the damage. Link a threat scenario. Define the attack path. All from dropdowns and linked catalogs — no free-typing into cells.

Threat identification view — clean, focused, no scoring clutter.

2. Score Feasibility & Determine Risk

Five factors per ISO 21434 Annex H: Elapsed TimeExpertiseKnowledgeWindow of OpportunityEquipment. Fill in the dropdowns — the feasibility level and the risk verdict calculate automatically.

RISKSHEET Feasibility scoring with auto-calculated result
Five dropdowns in, feasibility out. No manual lookups.

The verdict matrix maps Impact × Feasibility to a 1–5 risk level. Same threat, different attack path? Different verdict. Severity alone doesn’t determine risk — the attack path matters.

4x4 risk verdict matrix producing verdicts 1 (green) to 5 (red)
Color-coded verdicts — highest risks visible at a glance. ISO/SAE 21434

3. Treat & Verify

Every high-risk record gets a treatment decision:

Reducing
Define a goal + controls
Avoiding
Eliminate the path
Sharing
Document a claim
Retaining
Document a claim

Choose Reducing? You need a cybersecurity goal. Choose Retaining? You need a claim justifying why the risk is acceptable. RISKSHEET highlights missing artifacts so nothing slips through.

Goals trace to requirements. Requirements trace to test cases. Every link is a real Polarion relationship — not a cell reference that breaks when someone inserts a row.

End-to-end traceability. Every arrow is a Polarion link role.

What Changes When You Leave Excel

1 Traceability is structural. Threat → goal → requirement → test case. When an auditor asks “how is this mitigated?”, the answer is one click.

2 Formulas are enforced. Feasibility and verdict are calculated, not typed. No one accidentally overwrites a score.

3 Views separate concerns. Threat identification shows threat columns. Scoring shows scoring columns. Your team works in context, not in a 30-column spreadsheet.

4 Multi-level TARA out of the box. System, subsystem, component — same template, same scoring, different scope. Create a new module, start working.

The full picture: threats, scores, verdicts, treatment — all in one view.

Join Jiri and Radek at Realize Live in Amsterdam

Nextedy @ Realize Live


See it Live, try it yourself

The complete TARA template — four modules, linked catalogs, automated scoring, traceability to requirements and test cases — ready to deploy.

Try Nextedy TARA Online


Jiří Walek and Radek Krotil lead Nextedy, a Siemens Polarion technology partner since 2018. they will both be at realize Live europe Nextedy builds native Polarion add-ons for regulated engineering at scale — risk management, requirements traceability, program planning, and compliance — with approximately 130,000 licensed users across customers in automotive, aerospace, medtech, and industrial. Learn more at nextedy.com/cybersecurity-risk-management.

Wesley Aarsen

Leave a Reply

This article first appeared on the Siemens Digital Industries Software blog at https://blogs.sw.siemens.com/polarion/how-to-run-iso-sae-21434-tara-in-polarion-better-and-faster/