Threat Analysis and Risk Assessment | ISO/SAE 21434 and WP.29 CSMS

TEAM UPSTREAM

For WP.29, as part of the CSMS requirement, it’s required to apply TARA throughout the vehicle lifecycle. When you build a vehicle, you need to apply TARA on the critical vehicle components and as a result of this TARA, you need to apply mitigation inside the vehicle.

But, you also need to emit logs, that will later be used in the post-production detection system, and, you also need to secure the supply chain.

In post-production, you need to leverage these logs and additional logs, to apply post-production detection.

And, over the entire lifecycle of the vehicle, you need to have a process to assess risk, categorize risk, and apply risk treatment decisions, as part of your TARA process.

WP.29 also provides a specific list of threats in Annex Five of the regulation, that actually outlines a comprehensive list of attacks that cover many of the interfaces of the vehicle.

This list of attacks is used as a baseline for securing the vehicle, both in development and in post-production.

 

Newsletter Icon

Subscribe
to our newsletter

Stay up-to-date on the latest trends, emerging risks, and updates

The New Risks of Automotive AI: Uncovering LLM and MCP Security

In this live webinar, Dan O’Reilly from Ford and Tomer Younger from Upstream examine how automotive cyber teams are evolving to address this shift.

More Details

Upstream’s 2026 Global Automotive Cybersecurity Report Predictions

The rapid adoption of AI, including Generative AI and large language models, is fundamentally changing how cybersecurity risks emerge in Automotive and Smart Mobility environments.…

More Details

Moving Minds: Giuseppe Serio hosts Darren Shelcusky

Moving Minds is a new series dedicated to the visionaries, experts, and builders shaping how we move. Guided by Giuseppe Serio, it brings forward the…

More Details

Upstream’s 2026 Global Automotive Cybersecurity Report Executive Summary

The rapid adoption of AI, including Generative AI and large language models, is fundamentally changing how cybersecurity risks emerge in Automotive and Smart Mobility environments.…

More Details

2026 Global Automotive & Smart Mobility Report – The AI Awakening

Dive into how AI is reshaping the automotive, smart mobility, and physical AI threat landscape, alongside the surge in ransom-related attacks.

More Details

Moving Minds: Giuseppe Serio hosts Elisa Romano

Moving Minds is a new series dedicated to the visionaries, experts, and builders shaping how we move. Guided by Giuseppe Serio, it brings forward the…

More Details