Residual Risk Evaluation – Necessary Iteration

Posted: September 5, 2024

In this article

The cybersecurity standard ISO/SAE 21434 illustrates the development workflow in the Automotive concept phase. Cybersecurity requirements are derived from goals based on the mitigations of TARA (Threat Analysis and Risk Assessment) processes. It does however not refer to how to evaluate the effectiveness and adequacy of the successful implementation of those requirements. To handle such cases, re-evaluation of risks with consideration of implemented requirements becomes a necessity.

SystemWeaver’s cybersecurity module provides not only the initial evaluation of risks but also a second evaluation after the definition of cybersecurity requirements. This offers a way for residual risk evaluation in the early concept phase, as a confirmation of the adequacy of deployed controls, rather than pushing it to verification and validation.

 

You may also be interested in

  • Subsystems and meta models

    White Paper: Subsystems, Meta-Models and Architecture

    Download this White Paper as a PDF Executive summary The meta-model supports the architecture without defining it. Clear, cohesive subsystems with explicit interfaces are what make model-based systems engineering usable at scale. This white paper distills ten practical insights drawn directly from SystemWeaver experts and practitioners, both at SystemWeaver and customers to SystemWeaver. [...]

  • Marcus and Anders interview

    5 Realities of AI in Modern Cybersecurity

    Every vendor in security claims AI changes everything. Ask the engineers actually building these systems and a different story comes up: a context gap. The AI returns a threat analysis that reads well and sounds confident but has little connection to the product.  That is where a recent conversation with Anders Hallgren and Marcus [...]

  • Strong engagement at the GAIA workshop: Trustworthy AI in Systems Engineering – Keeping Control and Traceability

    The central question during this workshop was one that matters more as engineering complexity grows: "How does AI fit into systems engineering without eroding control, traceability, or engineering accountability?" The answer is not to add AI as a black-box layer on top of engineering work. It is to ground AI in structured engineering context, [...]