Identifying the Assets of the Item
摘要
In this chapter, we lay the groundwork for a TARA by identifying the assets of the system under analysis, or item. We provide practical insights into asset identification and discuss relevant cybersecurity properties in addition to the CIA triad. In addition, we provide a valuable list of common assets for both automotive embedded and IT/OT systems. Following asset identification, we move on to identifying damage scenarios. We analyze the damage scenarios affecting the road user and provide practical examples of how to evaluate the impact across the categories required by the standard. Following the ISO/SAE 21434 standard, we show how we can extend the view of the damage scenario to analyze the impact on an organization as a whole. For the business impact, we describe new impact categories, such as intellectual property and image/reputation. At the end of the chapter, we provide a complete asset identification for three practical case studies.