Skip to content

Evidence request lists

ISO/SAE 21434

Evidence request list. 50 controls, 50 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Component Development

21434-10.4
Hardware and Software Component Requirements

Hardware and software components implement allocated cybersecurity requirements with secure coding practices and verification.

Artefacts an auditor will ask for
  • Component cybersecurity requirements allocated and traceable
  • Secure coding standard adopted (for example MISRA C plus security)
  • Static analysis results
  • Fuzz testing results for protocol stacks
  • Hardware security feature configuration evidence
Where this commonly fails
  • MISRA compliance enforced but security rules excluded
  • Fuzzing limited to one protocol
  • Hardware security features available but not enabled
  • Static analysis findings suppressed without justification

Concept Phase

21434-9.3
Item Definition

The item under cybersecurity consideration is defined including its boundary, interfaces, operating environment, and assumptions.

Artefacts an auditor will ask for
  • Item definition document
  • Boundary diagrams with internal and external interfaces
  • Operating environment description
  • Assumptions log
  • Dependencies on other items
Where this commonly fails
  • Boundary informal, leading to scope disputes during TARA
  • External interfaces enumerated but not characterised
  • Assumptions not revisited when environment changes
  • Dependencies ignored leading to gaps
21434-9.4
Cybersecurity Goals and Claims

Cybersecurity goals and claims are derived from the TARA and provide the basis for cybersecurity requirements at item level.

Artefacts an auditor will ask for
  • Cybersecurity goals derived from threat scenarios
  • Cybersecurity claims with rationale
  • Cybersecurity Assurance Level (CAL) determinations
  • Traceability from TARA to goals
  • Review record by independent assessor
Where this commonly fails
  • Goals stated as features not protections
  • CAL not justified or treated as one-size-fits-all
  • Traceability matrix incomplete
  • Independent review skipped

Development

21434-10
Product Development at System Level

System-level cybersecurity requirements are derived from cybersecurity goals and verified through design, integration, and testing.

Artefacts an auditor will ask for
  • System cybersecurity requirements specification
  • Architecture documentation with security mechanisms
  • Verification plan and execution records
  • Trust boundary diagrams
  • Cryptographic mechanism selection rationale
Where this commonly fails
  • Requirements duplicate goals without decomposition
  • Cryptographic choices outdated or unjustified
  • Verification focuses on positive cases only
  • Trust boundaries not maintained as architecture evolves

ISO/SAE 21434: Access Control

ISO21434-11
Access control policy and enforcement

Access control policy and enforcement. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-12
User access management and provisioning

User access management and provisioning. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-13
Authentication and password management

Authentication and password management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-14
Privileged access management

Privileged access management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-15
Access review and recertification

Access review and recertification. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Access Control.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature

ISO/SAE 21434: Asset Management

ISO21434-06
Asset inventory and ownership

Asset inventory and ownership. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-07
Acceptable use of assets

Acceptable use of assets. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-08
Information classification and labeling

Information classification and labeling. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-09
Asset handling procedures

Asset handling procedures. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-10
Media management and disposal

Media management and disposal. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Asset Management.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature

ISO/SAE 21434: Communications Security

ISO21434-27
Network security management

Network security management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-28
Network service security

Network service security. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-29
Segregation in networks

Segregation in networks. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-30
Information transfer policies

Information transfer policies. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-31
Secure messaging

Secure messaging. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Communications Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature

ISO/SAE 21434: Cryptography

ISO21434-16
Cryptographic policy and key management

Cryptographic policy and key management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-17
Encryption of data at rest

Encryption of data at rest. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-18
Encryption of data in transit

Encryption of data in transit. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-19
Certificate management

Certificate management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-20
Key lifecycle management

Key lifecycle management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Cryptography.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature

ISO/SAE 21434: Information Security Policies

ISO21434-01
Information security policy framework

Information security policy framework. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-02
Management direction and commitment

Management direction and commitment. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-03
Policy review and update procedures

Policy review and update procedures. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-04
Roles and responsibilities definition

Roles and responsibilities definition. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-05
Contact with authorities and special interest groups

Contact with authorities and special interest groups. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Information Security Policies.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature

ISO/SAE 21434: Operations Security

ISO21434-21
Operational procedures and responsibilities

Operational procedures and responsibilities. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-22
Protection from malware

Protection from malware. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-23
Backup and recovery procedures

Backup and recovery procedures. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-24
Logging and monitoring

Logging and monitoring. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-25
Technical vulnerability management

Technical vulnerability management. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature
ISO21434-26
Audit considerations

Audit considerations. Control from ISO/SAE 21434 framework, domain: ISO/SAE 21434: Operations Security.

Artefacts an auditor will ask for
  • Vehicle cybersecurity policy and roles matrix
  • Asset and threat catalogue
  • Cybersecurity case and TARA report
  • Cryptographic key management plan
  • Vulnerability and incident response playbook
Where this commonly fails
  • Cybersecurity not integrated with functional safety lifecycle
  • Threat models missing for in-vehicle networks
  • Key management for ECUs lacks rotation
  • Field monitoring and incident response are immature

Lifecycle

21434-14
End of Cybersecurity Support and Decommissioning

The organisation defines and communicates end of cybersecurity support and decommissioning conditions for items including data destruction.

Artefacts an auditor will ask for
  • End-of-support policy by item or model year
  • Customer communication templates
  • Decommissioning procedure including key destruction
  • Data sanitisation evidence on returned units
  • Records of items past end of support
Where this commonly fails
  • End of support not communicated to customers
  • Vehicles in service past stated date without explicit risk acceptance
  • Sanitisation absent on returned hardware
  • Keys remain valid after end of support

Operations

21434-13
Operations and Maintenance

Cybersecurity is maintained through operations including vulnerability management, incident response, and over-the-air updates.

Artefacts an auditor will ask for
  • Vulnerability management procedure aligned to ISO/IEC 30111
  • Incident response plan with automotive-specific playbooks
  • Over-the-air update mechanism with integrity protection
  • Field monitoring data flows
  • Customer notification procedures
Where this commonly fails
  • OTA mechanism lacks rollback to known-good
  • Incident response untested for safety-related cyber events
  • No field monitoring telemetry
  • Customer notification reactive only
21434-7
Continuous Cybersecurity Activities

The organisation performs continuous monitoring of cybersecurity information sources, internal events, and triggers to inform vulnerability and incident management.

Artefacts an auditor will ask for
  • List of monitored sources (Auto-ISAC, CVE, supplier feeds)
  • Daily triage log of cybersecurity events
  • Defined triggers for further cybersecurity activities
  • Escalation matrix from monitoring to response
  • Periodic effectiveness review
Where this commonly fails
  • Monitoring relies on ad hoc engineer attention
  • No formal trigger definitions, judgement calls only
  • Auto-ISAC membership but no integration into workflows
  • Effectiveness not measured

Organisational

21434-5
Cybersecurity Governance

The organisation establishes cybersecurity governance for road vehicle development including policy, accountability, and integration with quality management and functional safety.

Artefacts an auditor will ask for
  • Cybersecurity policy signed by executive sponsor
  • Organisational chart showing cybersecurity function
  • Integration plan with ASPICE and ISO 26262 processes
  • Annual management review minutes
  • Resource and competence plan
Where this commonly fails
  • Cybersecurity function under-resourced compared to functional safety
  • Policy exists but not enforced in supplier contracts
  • No integration with safety, only parallel processes
  • Management review focused on schedule not cybersecurity posture

People

21434-6
Cybersecurity Culture and Competence

The organisation fosters a cybersecurity culture and ensures personnel involved in vehicle cybersecurity have the required competence.

Artefacts an auditor will ask for
  • Competence matrix for cybersecurity roles
  • Training curriculum specific to automotive cybersecurity
  • Annual training completion records
  • Awareness campaigns evidence
  • Performance objectives including cybersecurity
Where this commonly fails
  • Generic IT security training substituted for automotive
  • Competence matrix exists but gaps unaddressed
  • Awareness limited to engineering staff
  • No competence requirements for suppliers

Production

21434-12
Production

Cybersecurity controls are maintained through production processes including provisioning of keys, identifiers, and configurations.

Artefacts an auditor will ask for
  • Production cybersecurity plan
  • Key provisioning procedures and HSM usage records
  • Anti-counterfeiting measures
  • Production network segregation evidence
  • Audit logs of provisioning events
Where this commonly fails
  • Keys generated outside HSM and exported
  • Production network shared with corporate IT
  • Counterfeit detection absent
  • Provisioning logs not retained

Risk

21434-8
Risk Assessment Methods

The organisation applies defined methods for asset identification, threat scenario identification, impact rating, attack path analysis, and risk determination.

Artefacts an auditor will ask for
  • Documented risk assessment method aligned to Clause 15
  • Asset register per item or component
  • Threat scenario library covering STRIDE or equivalent
  • Impact rating scheme covering safety, financial, operational, privacy
  • Method validation records
Where this commonly fails
  • Method documented but applied inconsistently across teams
  • Asset register limited to ECUs, missing data flows
  • Impact scheme heavily weighted to safety, privacy ignored
  • No calibration of analysts producing similar ratings

Risk Treatment

21434-15.9
Cybersecurity Assurance Level (CAL) and Risk Treatment

Risk treatment decisions are made for each threat scenario and Cybersecurity Assurance Levels (CAL 1-4) are determined to scale rigour of cybersecurity activities.

Artefacts an auditor will ask for
  • Risk treatment plan covering avoid, reduce, share, retain
  • CAL determination per cybersecurity goal
  • Justification for higher CAL choices
  • Residual risk register
  • Senior sign-off on retained risks
Where this commonly fails
  • CAL defaulted to CAL 2 across items without analysis
  • Treatment plan incomplete for retained risks
  • Residual risk not communicated to OEM customer
  • No senior sign-off on acceptance

Supply Chain

21434-Annex-E
Distributed Cybersecurity Activities and Supplier Management

Cybersecurity activities distributed between OEM, Tier 1, and lower-tier suppliers are managed through cybersecurity interface agreements (CIA) and joint assessments.

Artefacts an auditor will ask for
  • Cybersecurity interface agreements with each tier supplier
  • RASIC matrix for distributed activities
  • Supplier capability assessments
  • Joint TARA workshops where applicable
  • Supplier deliverables review records
Where this commonly fails
  • CIA signed but not maintained as scope changes
  • Lower-tier suppliers not in scope of supplier programme
  • Joint TARA absent for shared assets
  • Deliverables accepted without independent review

TARA

21434-15.3
Asset Identification (TARA Step 1)

Assets and their cybersecurity properties (confidentiality, integrity, availability, authenticity, authorisation, non-repudiation) are identified as the basis for threat analysis.

Artefacts an auditor will ask for
  • Asset register with cybersecurity properties per asset
  • Mapping of assets to architecture
  • Property rationale documentation
  • Review record of asset list
  • Update procedure for asset changes
Where this commonly fails
  • Asset list limited to ECUs, missing data and credentials
  • Properties asserted without rationale
  • Asset list static across model years
  • No link between asset register and TARA outputs
21434-15.5
Threat Scenario Identification (TARA Step 2)

Threat scenarios are identified that could compromise the cybersecurity properties of assets including direct and indirect attack paths.

Artefacts an auditor will ask for
  • Threat scenario library reused across projects
  • Project-specific threat scenarios with rationale
  • Coverage analysis against asset properties
  • Workshop notes from threat identification sessions
  • Independent review of scenario completeness
Where this commonly fails
  • Reused library without project tailoring
  • Scenarios written only for known attacks
  • No coverage tracking
  • Single analyst with no peer review
21434-15.6
Impact Rating (TARA Step 3)

The impact of threat scenarios is rated against safety, financial, operational, and privacy damage categories.

Artefacts an auditor will ask for
  • Damage scenario descriptions per threat
  • Impact rating scale and calibration
  • Rated impact per scenario across SFOP categories
  • Linkage to functional safety hazard assessments
  • Quality review of ratings
Where this commonly fails
  • SFOP applied as four labels without calibrated scales
  • Privacy systematically rated low without analysis
  • No linkage to ISO 26262 hazard ratings
  • Ratings inconsistent across analysts
21434-15.7
Attack Path Analysis (TARA Step 4)

Attack paths leading to threat scenarios are analysed to understand feasibility and inform risk treatment.

Artefacts an auditor will ask for
  • Attack tree or attack path diagrams per scenario
  • Identified entry points (cellular, Wi-Fi, Bluetooth, OBD, USB, charging)
  • Mitigation mapping along the path
  • Feasibility inputs (elapsed time, expertise, knowledge, opportunity, equipment)
  • Validation against known attacks
Where this commonly fails
  • Attack paths narrative only, no diagrams
  • Entry points incomplete (vehicle to grid often missed)
  • Mitigations claimed without verification
  • Feasibility inputs assumed not researched
21434-15.8
Attack Feasibility and Risk Determination (TARA Step 5)

Attack feasibility is rated and combined with impact to determine cybersecurity risk levels per threat scenario.

Artefacts an auditor will ask for
  • Feasibility rating with documented inputs per scenario
  • Risk matrix combining impact and feasibility
  • Risk determination per scenario
  • Threshold for acceptable risk
  • Risk treatment decision records
Where this commonly fails
  • Feasibility tied to vendor judgement without external benchmarks
  • Risk matrix biases towards low ratings
  • Acceptable risk threshold unstated
  • Treatment decisions without sign-off

Validation

21434-11
Cybersecurity Validation

Cybersecurity validation confirms cybersecurity goals are achieved at item level under representative operating conditions.

Artefacts an auditor will ask for
  • Validation plan covering all cybersecurity goals
  • Test environment representative of vehicle operation
  • Penetration test reports by independent team
  • Defect tracking and closure records
  • Validation sign-off by responsible person
Where this commonly fails
  • Validation overlaps verification rather than confirming goals
  • Pen testing internal only, no third party
  • Test environment not representative
  • Open defects carried into release without justification
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.