Prerequisites
- The TARA module is in Draft status with all records analyzed (verdicts computed)
- At least one user in the project has the
project_approverrole assigned - You have edit permissions on the riskSpecification document
Steps
1. Complete the TARA Analysis
Before sending for review, verify that the TARA module is complete:- All TARA records have
taraImpactand five attack feasibility factors scored - The
taraVerdictformula has computed a verdict for every record - Treatment decisions (
treatmentChoice) are recorded for all records - Cybersecurity goals are linked where
treatmentChoiceis Reducing or Avoiding - Claims are documented where
treatmentChoiceis Retaining or Sharing
2. Send for Review
- Open the TARA module in Polarion (document view, not Risksheet)
- Click the workflow action Send for Review
- Polarion automatically transitions the document from Draft to In Review
AddDefaultSigners workflow function runs automatically, populating the signature request with all users holding the project_approver role. These signers are assigned the “Approver” signer role targeting the “approved” status.
You do not need to manually select reviewers. All
project_approver role holders are added as required signers automatically. To change who reviews documents, adjust the role membership in Polarion project administration.3. Review the TARA Content
As a reviewer with theproject_approver role:
- Open the TARA module in Risksheet view
- Walk through each view in the 5-step workflow order:
- 1. Identify Threats — verify stakeholder, CIAx, damage, threat, and path entries
- 2. Assess Feasibility — confirm attack factor scores are justified
- 3. Risk Assessment — check that impact ratings align with damage scenarios
- 4. Risk Treatment — validate treatment choices and linked goals/controls
- 5. Req & Verification — confirm downstream requirements and test cases exist
- Use CommentBased reviews (configured in the Risksheet) to leave inline feedback
4. Approve the Document
- Return to the document view (not Risksheet)
- Click the workflow action Approve
- Provide your electronic signature when prompted
atLeastOne signature policy means a single project_approver signature is sufficient. Once the minimum signatures are collected, the document transitions from In Review to Approved.
5. Publish the Document
After approval, a project lead can finalize the document:- Open the approved document
- Click the workflow action Publish
- The document transitions to Published status
Verification
After publishing, confirm:- Document status shows Published in the Risks Home navigator
- Electronic signatures are recorded and visible in the document’s signature panel
- The Cybersecurity Case dashboard reflects the approved TARA content
Related
- Rework a TARA Document — to return a document to Draft for corrections
- Risk Specification Document Workflow — workflow state machine reference
- TARA Document Lifecycle — conceptual overview