{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T15:19:46Z","timestamp":1784733586681,"version":"3.55.0"},"publisher-location":"400 Commonwealth Drive, Warrendale, PA, United States","reference-count":5,"publisher":"SAE International","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"abstract":"<jats:p>&lt;div class=\"section abstract\"&gt;&lt;div class=\"htmlview paragraph\"&gt;Threat Analysis Risk Assessment (TARA) for automotive systems is standardized in ISO\/SAE 21434. Traditionally these analyses have been bifurcated into either analysis focused on system functionality identifying impacts to assets based on the mission of the product, or analysis targeting vulnerabilities associated with the hardware and software of interfaces selected to be a part of a product. Furthermore, in the age of Software Defined Vehicles, the challenges to decouple use cases and the software that implements such from specific fixed hardware designs magnifies the disconnect between these risk methods. Use Case Based threat analysis, grounded in understanding features, stakeholders, and user stories, inherently yields security requirements tailored to specific functionalities and their contexts. While component-based threat analysis, derived from enumerations of vulnerabilities associated with interface choices, inherently yields security requirements tailored to specific defenses of these vulnerabilities. This paper will outline how a Use Case Based TARA partitions a user story into its assets and stakeholders and maintains traceability to risk through the development of that user story. This method's detailed approach ensures that cybersecurity requirements can be readily implemented as a part of feature design, addressing the concerns of feature owners directly. This paper will discuss the merits of asset based approach to cybersecurity over attack based recognizing the inherent strengths and limitations of both methods and underscores the need for a unified approach. Combining these analyses fosters a holistic view, ensuring that security requirements are both actionable and comprehensive. This paper provides the opportunity to point out the shift toward agile development and the need to provide incremental value on short intervals. This article delves into the intricacies of these concurrent threat analysis processes, highlighting the potential gaps and overlaps that may arise when treated in isolation. We argue that a fragmented approach not only leads to potential vulnerabilities but also results in redundancies, making the threat mitigation process inefficient.&lt;\/div&gt;&lt;\/div&gt;<\/jats:p>","DOI":"10.4271\/2024-01-2797","type":"proceedings-article","created":{"date-parts":[[2024,4,9]],"date-time":"2024-04-09T22:15:51Z","timestamp":1712700951000},"source":"Crossref","is-referenced-by-count":1,"title":["Integrating Functional and Component-Level Threat Analyses in Automotive Systems: A Holistic Approach to Risk Assessment"],"prefix":"10.4271","volume":"1","author":[{"given":"Bill","family":"Mazzara","sequence":"first","affiliation":[{"name":"Stellantis NV"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Issak","family":"Davidovich","sequence":"additional","affiliation":[{"name":"C2A Security"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2796","published-online":{"date-parts":[[2024,4,9]]},"reference":[{"key":"ref0","unstructured":"2021"},{"key":"ref1","unstructured":"McDonald ,  K. Epic Confusion Agile Alliance https:\/\/www.agilealliance.org\/"},{"key":"ref2","unstructured":"Scaled Agile Framework 2023 https:\/\/www.scaledagileframework.com\/"},{"key":"ref3","doi-asserted-by":"crossref","unstructured":"Mazzara ,  B.  and   Guo ,  Y. Cybersecurity by Agile Design SAE Technical Paper  2023-01-0035 2023 https:\/\/doi.org\/10.4271\/2023-01-0035","DOI":"10.4271\/2023-01-0035"},{"key":"ref4","unstructured":"What is a software-defined vehicle? 2020 https:\/\/www.automotiveworld.com\/news-releases\/what-is-a-software-defined-vehicle\/"}],"event":{"name":"WCX SAE World Congress Experience","location":"Detroit, Michigan, United States","acronym":"ANNUAL","number":"288443","start":{"date-parts":[[2024,4,16]]}},"container-title":["SAE Technical Paper Series"],"original-title":[],"link":[{"URL":"https:\/\/saemobilus.sae.org\/downloads\/papers\/2024-01-2797\/Full%20Text%20PDF","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T00:02:30Z","timestamp":1758672150000},"score":1,"resource":{"primary":{"URL":"https:\/\/saemobilus.sae.org\/papers\/integrating-functional-component-level-threat-analyses-automotive-systems-a-holistic-approach-risk-assessment-2024-01-2797"}},"subtitle":[],"proceedings-subject":"SAE Technical Paper Series","short-title":[],"issued":{"date-parts":[[2024,4,9]]},"references-count":5,"URL":"https:\/\/doi.org\/10.4271\/2024-01-2797","relation":{},"ISSN":["0148-7191","2688-3627"],"issn-type":[{"value":"0148-7191","type":"print"},{"value":"2688-3627","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,4,9]]},"article-number":"2024-01-2797"}}