In this chapter, we lay the groundwork for a TARA by identifying the assets of the system under analysis, or item. We provide practical insights into asset identification and discuss relevant cybersecurity properties in addition to the CIA triad. In addition, we provide a valuable list of common assets for both automotive embedded and IT/OT systems. Following asset identification, we move on to identifying damage scenarios. We analyze the damage scenarios affecting the road user and provide practical examples of how to evaluate the impact across the categories required by the standard. Following the ISO/SAE 21434 standard, we show how we can extend the view of the damage scenario to analyze the impact on an organization as a whole. For the business impact, we describe new impact categories, such as intellectual property and image/reputation. At the end of the chapter, we provide a complete asset identification for three practical case studies.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Identifying the Assets of the Item

  • Rodrigo do Carmo,
  • Alexander Schlensog

摘要

In this chapter, we lay the groundwork for a TARA by identifying the assets of the system under analysis, or item. We provide practical insights into asset identification and discuss relevant cybersecurity properties in addition to the CIA triad. In addition, we provide a valuable list of common assets for both automotive embedded and IT/OT systems. Following asset identification, we move on to identifying damage scenarios. We analyze the damage scenarios affecting the road user and provide practical examples of how to evaluate the impact across the categories required by the standard. Following the ISO/SAE 21434 standard, we show how we can extend the view of the damage scenario to analyze the impact on an organization as a whole. For the business impact, we describe new impact categories, such as intellectual property and image/reputation. At the end of the chapter, we provide a complete asset identification for three practical case studies.