Threat Analysis and Risk Assessment | ISO/SAE 21434 and WP.29 CSMS

TEAM UPSTREAM

For WP.29, as part of the CSMS requirement, it’s required to apply TARA throughout the vehicle lifecycle. When you build a vehicle, you need to apply TARA on the critical vehicle components and as a result of this TARA, you need to apply mitigation inside the vehicle.

But, you also need to emit logs, that will later be used in the post-production detection system, and, you also need to secure the supply chain.

In post-production, you need to leverage these logs and additional logs, to apply post-production detection.

And, over the entire lifecycle of the vehicle, you need to have a process to assess risk, categorize risk, and apply risk treatment decisions, as part of your TARA process.

WP.29 also provides a specific list of threats in Annex Five of the regulation, that actually outlines a comprehensive list of attacks that cover many of the interfaces of the vehicle.

This list of attacks is used as a baseline for securing the vehicle, both in development and in post-production.

 

Newsletter Icon

Subscribe
to our newsletter

Stay up-to-date on the latest trends, emerging risks, and updates

Upstream Recognized as Frost & Sullivan’s 2025 Enabling Technology Leader in AI-Driven After-Sales Vehicle Quality

Upstream has been named Frost & Sullivan’s 2025 Enabling Technology Leader for its pioneering work in after-sales quality detection and field investigations, powered by purpose-built…

More Details

Moving Minds: Giuseppe Serio hosts Gianfranco Pizzuto [Part 2]

Moving Minds is a new series dedicated to the visionaries, experts, and builders shaping how we move. Guided by Giuseppe Serio, it brings forward the…

More Details

Moving Minds: Giuseppe Serio hosts Gianfranco Pizzuto [Part 1]

Moving Minds is a new series dedicated to the visionaries, experts, and builders shaping how we move. Guided by Giuseppe Serio, it brings forward the…

More Details

Upstream 소개: 커넥티드 차량을 위한 사이버보안 및 데이터 관리 플랫폼

More Details

CISO Panel: Reinventing the vSOC with Agentic AI

As vehicle cybersecurity grows more complex, the role of the cyber teams and the vSOC is undergoing a profound transformation. In this candid CISO panel,…

More Details

LLMs in automotive: Turning hype into scalable business value

In this webinar, Upstream’s experts Sarit Kozokin (VP Product), Elad Tsur (Data Science Leader), and industry veteran Jennifer Tisdale explore practical LLM applications across various…

More Details