Skip to main content
Type ID: taraRecord Label: TARA Record Icon: type_risk.gif Risksheet role: Primary row type (riskType)

Custom Fields

Threat Identification Fields

Field IDNameTypeRisksheet ColumnHierarchy Level
ciaxPropertyCIAx Propertyenum:taraRecord-ciaxPropertyciaxProperty2
damageScenarioDamage Scenariotext/plaindamageScenario3
threatPathThreat Pathtext/plainthreatPath5
The ciaxProperty field captures which security dimension is threatened. See CIAx Security Properties for allowed values. The damageScenario field is free-text describing the harm that results if the threat is realized. It pairs with taraImpact as the qualitative rationale for the severity rating. The threatPath field describes the specific attack vector — the sequence of steps an attacker must complete. This is the lowest level of the Risksheet’s 5-level hierarchy.

Attack Feasibility Factor Fields

Five fields implement the EVITA Attack Potential methodology referenced in ISO/SAE 21434 Annex G:
Field IDNameTypeRisksheet HeaderScore Range
attackTimeElapsed Timeenum:taraRecord-attackTimeTIME0—19
attackExpertiseSpecialist Expertiseenum:taraRecord-attackExpertiseEXP0—8
attackKnowledgeKnowledge of Itemenum:taraRecord-attackKnowledgeKNOW0—11
attackWooWindow of Opportunityenum:taraRecord-attackWooWOO0—10
attackEquipmentEquipmentenum:taraRecord-attackEquipmentEQP0—9
Each factor has its own enumeration with distinct numeric weights. The feasibilityFormula in Risksheet sums all five scores to compute the aggregate taraFeasibility. See Attack Feasibility Factor Enums for all values and scores.

Risk Assessment Fields

Field IDNameTypeComputedRisksheet Column
taraImpactImpactenum:taraRecord-taraImpactNotaraImpact
taraFeasibilityAttack Feasibilityenum:taraRecord-taraFeasibilityYes (formula)taraFeasibility
taraVerdictRisk VerdictintegerYes (formula)taraVerdict
The taraImpact field is manually set by the analyst. Values: negligible, moderate, major, severe. See TARA Impact Levels. The taraFeasibility field is computed by the feasibilityFormula:
Aggregate ScoreFeasibility Level
0—13high (High)
14—19medium (Medium)
20—24low (Low)
25+veryLow (Very Low)
The taraVerdict field is computed by the verdictFormula (Impact x Feasibility matrix):
Impact \ FeasibilityVery LowLowMediumHigh
Severe3455
Major2345
Moderate1234
Negligible1111

Risk Treatment Fields

Field IDNameTypeRisksheet Column
treatmentChoiceTreatment Choiceenum:taraRecord-treatmentChoicetreatmentChoice
treatmentStatusTreatment Statusenum:taraRecord-treatmentStatustreatmentStatus
taraClaimsClaimstext/plaintaraClaims
taraControlsControlstext/plain(not in Risksheet views)
The treatmentChoice field records the risk treatment strategy:
ValueWhen to UseRequired Follow-up
reducingApply controls to reduce riskLink a cybersecurityGoal + riskControl
avoidingEliminate the threat sourceLink a cybersecurityGoal
sharingTransfer risk to another partyDocument rationale in taraClaims
retainingAccept risk after analysisDocument rationale in taraClaims
The Risksheet goalHighlight decorator shows an orange outline when treatmentChoice is Reducing or Avoiding but no cybersecurityGoal is linked. The claimHighlight decorator shows an orange outline when treatmentChoice is Retaining or Sharing but taraClaims is empty.

Cell Decorators

DecoratorFieldBehavior
impactDecoratortaraImpactColor by severity: negligible (green), moderate (amber), major (orange), severe (red)
feasibilityDecoratortaraFeasibilityveryLow/low (green), medium (amber), high (red)
verdictDecoratortaraVerdict5-color gradient: V1 (#4CAF50) through V5 (#b71c1c)
rowHeaderVerdictRow headerEntire row header colored by verdict level
goalHighlightcybersecurityGoalOrange outline when goal is required but missing
claimHighlighttaraClaimsOrange outline when claim is required but missing
RoleDirectionTarget Type
hasStakeholderoutgoingstakeholder
hasThreatScenariooutgoingthreatScenario
hasCybersecurityGoaloutgoingcybersecurityGoal
mitigatesincoming (from riskControl)

Read-Only Form Fields

In the default Polarion form layout (taraRecord-form-layout.xml), the following fields are read-only:
  • Input fields: attackTime, attackExpertise, attackKnowledge, attackWoo, attackEquipment, taraImpact, damageScenario, threatPath
  • Computed fields: taraFeasibility, taraVerdict, description
All editing is performed exclusively through the Risksheet interface.

Risksheet Hierarchy Position

The taraRecord participates in a 5-level hierarchy within the Risksheet:
LevelColumnGrouped By
1stakeholderWho is affected
2ciaxPropertyWhat security property
3damageScenarioWhat harm results
4threatScenarioHow the threat manifests
5threatPathSpecific attack vector