Skip to main content

Prerequisites

  • TARA records exist with threat identification completed (stakeholder, CIAx, damage scenario, threat scenario, threat path)
  • Attack feasibility has been scored for each record (all five factors: TIME, EXP, KNOW, WOO, EQP)
  • The taraFeasibility column shows a computed value (High, Medium, Low, or Very Low)

Steps

1. Open the Risk Assessment View

In your TARA Risksheet module, switch to the 3. Risk Assessment view from the view selector. This view displays the columns needed for risk verdict assessment:
ColumnPurpose
stakeholderAffected stakeholder
ciaxPropertyThreatened security property
damageScenarioDescription of potential harm
threatScenarioLinked threat scenario
threatPathSpecific attack vector
taraImpactImpact level (you set this)
taraFeasibilityComputed feasibility (read-only)
taraVerdictComputed verdict 1-5 (read-only)

2. Set the Impact Level for Each Record

Click the Impact (taraImpact) cell for each TARA record and select the appropriate severity level:
Impact LevelDescription
SevereLife-threatening or fatal injuries; severe legal/regulatory violation
MajorSevere injuries; significant regulatory consequences
ModerateLight to moderate injuries; moderate consequences
NegligibleNo injuries; negligible consequences
Assess impact based on the damage scenario description. Consider safety, financial, operational, and privacy dimensions as defined in ISO/SAE 21434.

3. Review the Computed Verdict

Once both taraImpact and taraFeasibility are set, the verdictFormula automatically computes the taraVerdict score using this risk matrix: diagram

4. Interpret the Verdict Color Coding

The verdictDecorator applies color coding to both the verdict cell and the row header (rowHeaderVerdict):
VerdictColorMeaningAction Required
1Green (#4CAF50)Negligible riskNo action needed
2Light Green (#8BC34A)Low riskAcceptable
3Amber (#FF9800)Medium riskInvestigation required
4Red (#f44336)High riskControls required
5Dark Red (#b71c1c)Critical riskImmediate action
Both taraImpact and taraFeasibility must be set before the verdict computes. If either field is empty, the taraVerdict column remains blank.

5. Verify Your Results

Scan the row headers on the left side of the Risksheet. The rowHeaderVerdict decorator colors every row by its verdict, giving you a visual heat map of the entire module. You should now see:
  • Green row headers for low-risk records (Verdict 1-2)
  • Amber row headers for medium-risk records (Verdict 3)
  • Red row headers for high-risk records (Verdict 4-5)
Use the Overview view to see the complete risk picture, including verdict, treatment choice, and cybersecurity goal columns side by side.

What Happens Next

Records with Verdict 4-5 require risk treatment. Proceed to Define Risk Treatment to select treatment strategies and link cybersecurity goals or document claims.

See Also