How to Run ISO/SAE 21434 TARA in Polarion

Most teams conduct threat analysis and risk assessment (TARA) using spreadsheets, which creates maintainability challenges. As requirements change, a formula that references a deleted sheet becomes problematic. This article proposes conducting TARA within Polarion instead.

Five Steps, Five Views

TARA implementation follows five sequential steps, each with its own dedicated view that displays only relevant columns for that phase.

TARA 5-step workflow: Identify, Score, Assess, Treat, Verify

1. Identify Threats

Users select stakeholder catalogs and CIAx properties, then describe damage and link threat scenarios. The system emphasizes structured data entry through dropdowns rather than free-text fields.

Identify threats screenshot

2. Score Feasibility & Determine Risk

Five factors from ISO 21434 Annex H guide scoring:

  • Elapsed Time

  • Expertise

  • Knowledge

  • Window of Opportunity

  • Equipment

Five dropdowns in, feasibility out. No manual lookups. Automated calculations map Impact × Feasibility to risk levels (1–5), recognizing that severity alone doesn’t determine risk.

TARA feasibility scoring diagramTARA verdict matrix diagramTARA feasibility scoring screenshot

3. Treat & Verify

  • Reducing: Define goals and controls

  • Avoiding: Eliminate attack paths

  • Sharing: Document claims

  • Retaining: Document acceptance justification

Goals trace to requirements; requirements trace to test cases through actual Polarion relationships.

TARA treat and verify screenshot

What Changes When You Leave Excel

  • Traceability becomes structural rather than cell-based

  • Formulas are enforced, preventing manual overwrites

  • Views organize information by workflow phase

  • Multi-level TARA (system, subsystem, component) operates from a single template

TARA screenshot: leaving Excel comparison

Try a complete TARA template with four modules, linked catalogs, automated scoring, and requirement traceability.